Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

380 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.6%—Bogofilter Email Filter31/12/200516/6/2026
Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.
ModificadaAlta (7.5)5.5%—Bogofilter Email Filter31/12/200516/6/2026
Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter…
ModificadaAlta (9.3)3.3%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes31/12/200516/6/2026
Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when…
ModificadaAlta (9.3)7.9%—Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes31/12/200516/6/2026
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename…
ModificadaBaja (2.6)1.5%—Symantec Antivirus Scan EngineSymantec Mail SecuritySymantec Norton AntivirusSymantec Norton Internet Security+32/5/200516/6/2026
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a…
ModificadaMedia (5)1.9%—Bogofilter Email FilterUbuntu Linux1/3/200516/6/2026
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
ModificadaAlta (7.5)19%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+78/2/200516/6/2026
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
ModificadaAlta (10)6.0%—Bolthole Filter10/1/200516/6/2026
Buffer overflow in the save_embedded_address function in filter.c for elm/bolthole filter 2.6.1 allows remote attackers to execute arbitrary code via a crafted email message.
ModificadaAlta (7.5)4.3%—Linuxprinting.org Foomatic-filtersSUN Java Desktop SystemConectiva LinuxTrustix Secure Linux16/9/200416/6/2026
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
ModificadaMedia (5)2.6%—Surfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.
ModificadaMedia (4.3)3.6%💥 ExploitSurfcontrol Superscout Email Filter31/3/200316/6/2026
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.
ModificadaMedia (5)5.9%💥 ExploitSurfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.
ModificadaMedia (5)2.6%—Surfcontrol Superscout Email Filter31/3/200316/6/2026
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.
ModificadaAlta (7.5)2.0%—Darren Reed Ipfilter31/12/200216/6/2026
IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to an FTP server, which generates a response that contains the string, causing IPFilter to treat the response as if it were a legitimate PASV command from the server.
ModificadaMedia (5)2.6%—Surfcontrol Superscout Email Filter31/12/200216/6/2026
SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow.
ModificadaAlta (7.2)0.30%—Bogofilter Bogopass Email Filter31/12/200216/6/2026
bogopass in bogofilter 0.9.0.4 allows local users to overwrite arbitrary files via a symlink attack on the bogopass temporary file.
ModificadaMedia (5)1.3%—Sonicwall Content Filtering31/12/200216/6/2026
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
ModificadaAlta (7.5)1.1%💥 ExploitSurfcontrol Superscout WEB FilterSurfcontrol WEB Filter10/10/200216/6/2026
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to SimpleBar.dll, and possibly other DLLs.
ModificadaAlta (7.5)2.5%—Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter10/10/200216/6/2026
The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtain valid usernames and crack the passwords.
ModificadaMedia (5)3.5%💥 ExploitSurfcontrol Superscout WEB FilterSurfcontrol WEB Filter10/10/200216/6/2026
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... (triple dot) sequences.
ModificadaMedia (5)1.8%—Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter10/10/200216/6/2026
The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer overflow.
ModificadaAlta (7.5)0.98%—Surfcontrol Superscout WEB FilterSurfcontrol WEB Filter10/10/200216/6/2026
UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function.
ModificadaMedia (5)2.2%—Phildev Ipfilter12/8/200216/6/2026
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.
ModificadaMedia (4.6)0.35%—Surfcontrol Superscout WEB Filter26/2/200216/6/2026
SurfControl SuperScout only filters packets containing both an HTTP GET request and a Host header, which allows local users to bypass filtering by fragmenting packets so that no packet contains both data elements.
ModificadaMedia (5)1.1%—Netfilter Iptables5/11/200116/6/2026
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.
Orbitaley — Vulnerabilidades