Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
380 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.6% | — | Bogofilter Email Filter | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex. | |
| Modificada | Alta (7.5) | 5.5% | — | Bogofilter Email Filter | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter… | |
| Modificada | Alta (9.3) | 3.3% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when… | |
| Modificada | Alta (9.3) | 7.9% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes | 31/12/2005 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename… | |
| Modificada | Baja (2.6) | 1.5% | — | Symantec Antivirus Scan EngineSymantec Mail SecuritySymantec Norton AntivirusSymantec Norton Internet Security+3 | 2/5/2005 | 16/6/2026 | Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a… | |
| Modificada | Media (5) | 1.9% | — | Bogofilter Email FilterUbuntu Linux | 1/3/2005 | 16/6/2026 | The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address. | |
| Modificada | Alta (7.5) | 19% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+7 | 8/2/2005 | 16/6/2026 | Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. | |
| Modificada | Alta (10) | 6.0% | — | Bolthole Filter | 10/1/2005 | 16/6/2026 | Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message. | |
| Modificada | Alta (7.5) | 4.3% | — | Linuxprinting.org Foomatic-filtersSUN Java Desktop SystemConectiva LinuxTrustix Secure Linux | 16/9/2004 | 16/6/2026 | Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/3/2003 | 16/6/2026 | The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Darren Reed Ipfilter | 31/12/2002 | 16/6/2026 | IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server. | |
| Modificada | Media (5) | 2.6% | — | Surfcontrol Superscout Email Filter | 31/12/2002 | 16/6/2026 | SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow. | |
| Modificada | Alta (7.2) | 0.30% | — | Bogofilter Bogopass Email Filter | 31/12/2002 | 16/6/2026 | bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file. | |
| Modificada | Media (5) | 1.3% | — | Sonicwall Content Filtering | 31/12/2002 | 16/6/2026 | SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs. | |
| Modificada | Alta (7.5) | 2.5% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences. | |
| Modificada | Media (5) | 1.8% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow. | |
| Modificada | Alta (7.5) | 0.98% | — | Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter | 10/10/2002 | 16/6/2026 | UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function. | |
| Modificada | Media (5) | 2.2% | — | Phildev Ipfilter | 12/8/2002 | 16/6/2026 | IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs. | |
| Modificada | Media (4.6) | 0.35% | — | Surfcontrol Superscout WEB Filter | 26/2/2002 | 16/6/2026 | SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements. | |
| Modificada | Media (5) | 1.1% | — | Netfilter Iptables | 5/11/2001 | 16/6/2026 | iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator. |