Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.41%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.
ModificadaMedia (4.9)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the…
ModificadaMedia (4.3)1.3%—Webligo Bloghoster11/8/200616/6/2026
Cross-site scripting (XSS) vulnerability in Webligo BlogHoster 2.2 allows remote attackers to inject arbitrary web script or HTML via the "From: part of the comment post," probably involving the nickname parameter to previewcomment.php.
ModificadaBaja (2.1)0.39%—Symantec Ghost Solutions SuiteSymantec Norton Ghost19/3/200616/6/2026
Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database.
ModificadaMedia (4.6)0.36%—Symantec Ghost Solutions SuiteSymantec Norton Ghost19/3/200616/6/2026
The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks.
ModificadaBaja (3.2)0.32%—Symantec Ghost Solutions SuiteSymantec Norton Ghost19/3/200616/6/2026
SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information.
ModificadaAlta (7.2)0.47%—Aladdin Enterprises Ghostscript9/2/200516/6/2026
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.
ModificadaMedia (5)3.3%💥 ExploitRedstorm Desert SiegeRedstorm Ghost ReconRedstorm THE SUM OF ALL Fears31/12/200416/6/2026
Multiple Red Storm web-based games, including Ghost Recon 1.4 and earlier, Desert Siege, and The Sum of all Fears 1.1.1.0 and earlier, do not properly check return values from certain functions, which allows remote attackers to cause a denial of service (hang) via packets that contain text strings with incorrect size…
ModificadaAlta (7.5)2.4%—GhostviewGV17/11/200316/6/2026
gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file.
ModificadaMedia (4.6)2.0%💥 ExploitGGVGhostviewGV10/10/200216/6/2026
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.
ModificadaAlta (7.5)1.6%—Symantec Norton Ghost25/6/200216/6/2026
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.
ModificadaAlta (7.5)2.1%—Aladdin Enterprises Ghostscript29/5/200216/6/2026
ghostscript before 6.53 allows attackers to execute arbitrary commands by using .locksafe or .setsafe to reset the current pagedevice.
ModificadaBaja (2.6)0.32%—Aladdin Enterprises Ghostscript18/9/200116/6/2026
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.
ModificadaMedia (5)1.8%—Symantec Norton Ghost2/8/200116/6/2026
Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.
ModificadaBaja (3.7)0.32%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack.
ModificadaMedia (4.6)0.40%—Aladdin Enterprises Ghostscript9/1/200116/6/2026
ghostscript before 5.10-16 uses an empty LD_RUN_PATH environmental variable to find libraries in the current directory, which could allow local users to execute commands as other users by placing a Trojan horse library into a directory from which another user executes ghostscript.
ModificadaAlta (7.5)2.8%—Aladdin Enterprises Ghostscript31/8/199516/6/2026
The ghostscript command with the -dSAFER option allows remote attackers to execute commands.
Orbitaley — Vulnerabilidades