Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.37% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop | 31/12/2005 | 16/6/2026 | ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary… | |
| Modificada | Baja (2.6) | 2.6% | — | RIM Blackberry Desktop ManagerRIM Blackberry Device SoftwareRIM Blackberry | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed. | |
| Modificada | Alta (7.8) | 3.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Router | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Plain Black WebguiAI | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6 allows attackers to execute arbitrary code via unknown attack vectors. | |
| Modificada | Alta (10) | 2.7% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | announcement.pl in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to gain administrator privileges by setting the context parameter to "admin". | |
| Modificada | Alta (7.5) | 1.5% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | The login page in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to bypass authentication and gain privileges as other users via a modified user_id parameter and a "/" in the encoded_pw parameter. | |
| Modificada | Media (4.3) | 0.95% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to inject arbitrary web script or HTML via the context parameter to announcement.pl, which is reflected in the resulting page. | |
| Modificada | Media (5) | 1.2% | — | Blackboard Academic Suite | 19/12/2005 | 16/6/2026 | Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to list all available categories via a blank category_id parameter to category.pl. NOTE: it is not clear whether this information is sensitive or not, so this might not be an… | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Blackboard Academic Suite | 13/12/2005 | 16/6/2026 | Blackboard Learning and Community Portal System in Academic Suite 6.3.1.424, 6.2.3.23, and other versions before 6 allows remote attackers to redirect users to other URLs and conduct phishing attacks via a modified url parameter to frameset.jsp, which loads the URL into a frame and causes it to appear to be part of a… | |
| Modificada | Alta (7.5) | 1.7% | — | Plainblack Webgui | 7/9/2005 | 16/6/2026 | Multiple eval injection vulnerabilities in PlainBlack Software WebGUI before 6.7.3 allow remote attackers to execute arbitrary Perl code via (1) Help.pm, (2) International.pm, or (3) WebGUI.pm. | |
| Modificada | Alta (7.5) | 4.8% | 💥 Exploit | Black Cactus Warrior KingsBlack Cactus Warrior Kings Battles | 24/5/2005 | 16/6/2026 | Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Black Cactus Warrior Kings Battles | 24/5/2005 | 16/6/2026 | Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference. | |
| Modificada | Media (5) | 1.2% | — | Blackboard | 31/12/2004 | 16/6/2026 | BlackBoard 1.5.1 allows remote attackers to gain sensitive information via a direct request to (1) checkdb.inc.php, (2) admin.inc.php or (3) cp.inc.php, which reveals the path in a PHP error message. | |
| Modificada | Media (4.6) | 0.42% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop | 31/12/2004 | 16/6/2026 | Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value. | |
| Modificada | Alta (7.5) | 1.7% | — | Blackboard Internet Newsboard System | 31/12/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Sapporoworks Black Jumbodog | 31/12/2004 | 16/6/2026 | Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD. | |
| Modificada | Media (4.6) | 0.43% | — | ISS Blackice PC Protection | 31/12/2004 | 16/6/2026 | The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers. | |
| Modificada | Media (5) | 2.0% | — | RIM Blackberry | 13/10/2004 | 16/6/2026 | RIM Blackberry 7230 running RIM Blackberry OS 3.7 SP1 allows remote attackers to cause a denial of service (device reboot and possibly data corruption) via a calendar message with a long Location field, which triggers a watchdog while the message is being stored. | |
| Modificada | Alta (7.1) | 0.85% | 💥 Exploit | ISS Blackice PC ProtectionISS Blackice Server Protection | 11/8/2004 | 16/6/2026 | BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall… | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/4/2004 | 16/6/2026 | Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a… | |
| Modificada | Alta (7.5) | 8.0% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/3/2004 | 16/6/2026 | Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6,… | |
| Modificada | Media (4.3) | 1.4% | — | IBM Internet Security Systems Blackice DefenderISS Blackice Server Protection | 31/12/2003 | 16/6/2026 | BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. | |
| Modificada | Media (4.6) | 0.48% | — | Selom Ofori Blackmoon FTP Server | 21/5/2003 | 16/6/2026 | BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, generates an "Account does not exist" error message when an invalid username is entered, which makes it easier for remote attackers to conduct brute force attacks. | |
| Modificada | Media (4.6) | 0.31% | — | Selom Ofori Blackmoon FTP Server | 20/5/2003 | 16/6/2026 | BlackMoon FTP Server 2.6 Free Edition, and possibly other distributions and versions, stores user names and passwords in plaintext in the blackmoon.mdb file, which can allow local users to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | ISS Blackice Agent | 4/10/2002 | 16/6/2026 | The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user. |