Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
414 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Cisco Adaptive Security Appliance 5500 | 29/12/2009 | 16/6/2026 | The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to access arbitrary backend servers, which might allow remote authenticated users to bypass intended access restrictions and access unauthorized web sites via a crafted URL… | |
| Modificada | Media (6.8) | 4.8% | — | Aladdin Safenet Securewire Access GatewayCisco Adaptive Security ApplianceSonicwall E-class SSL VPNSonicwall SSL VPN+1 | 4/12/2009 | 16/6/2026 | Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that… | |
| Modificada | Media (6) | 3.8% | 💥 Exploit | Cisco Adaptive Security Appliance | 25/6/2009 | 16/6/2026 | WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN… | |
| Modificada | Media (4.3) | 2.0% | — | Cisco Adaptive Security Appliance | 25/6/2009 | 16/6/2026 | WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI,… | |
| Modificada | Media (4.3) | 8.8% | 💥 Exploit | Cisco Adaptive Security Appliance | 25/6/2009 | 16/6/2026 | Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the… | |
| Modificada | Media (4.3) | 1.1% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before 7.2(4)26, 8.0 before 8.0(4)22, and 8.1 before 8.1(2)12, when SQL*Net inspection is enabled, allows remote attackers to cause a denial of service (traceback and device reload) via a series of SQL*Net… | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)26, 8.0 before 8.0(4)24, and 8.1 before 8.1(2)14, when H.323 inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted… | |
| Modificada | Alta (7.8) | 2.7% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet. | |
| Modificada | Media (5.7) | 0.74% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 before 8.1(2)15, when an SSL VPN or ASDM access is configured, allows remote attackers to cause a denial of service (device reload) via a crafted (1) SSL or (2) HTTP packet. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 9/4/2009 | 16/6/2026 | Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN… | |
| Modificada | Media (4.3) | 9.0% | 💥 Exploit | Cisco Adaptive Security ApplianceCisco IOS | 1/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Adaptive Security Appliance 5500 SeriesCisco PIX Security Appliance | 23/10/2008 | 16/6/2026 | Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via an unspecified sequence of packets, related to the "initialization code for the hardware crypto… | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco Adaptive Security Appliance 5500 SeriesCisco PIX Security Appliance | 23/10/2008 | 16/6/2026 | Unspecified vulnerability in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2(4)9 and 7.2(4)10 allows remote attackers to cause a denial of service (device reload) via a crafted IPv6 packet. | |
| Modificada | Alta (7.1) | 2.6% | — | Cisco Adaptive Security Appliance 5500 | 4/9/2008 | 16/6/2026 | Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636. | |
| Modificada | Alta (7.1) | 3.2% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 4/9/2008 | 16/6/2026 | Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted… | |
| Modificada | Alta (7.1) | 2.8% | — | Cisco Adaptive Security Appliance 5500 | 4/9/2008 | 16/6/2026 | Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or… | |
| Modificada | Alta (7.8) | 3.4% | — | Cisco Adaptive Security Appliance 5500Cisco PIX | 4/9/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the SIP inspection functionality in Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.0 before 7.0(7)16, 7.1 before 7.1(2)71, 7.2 before 7.2(4)7, 8.0 before 8.0(3)20, and 8.1 before 8.1(1)8 allow remote attackers to cause a denial of service (device reload) via… | |
| Modificada | Alta (7.1) | 2.8% | — | Cisco Adaptive Security Appliance 5500 | 4/9/2008 | 16/6/2026 | The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka… | |
| Modificada | Alta (7.8) | 2.3% | — | Cisco PIX Security ApplianceCisco Adaptive Security Appliance Software | 4/6/2008 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.x before 7.2(4), and 8.0.x before 8.0(3)10 allows remote attackers to cause a denial of service via a crafted TCP ACK packet to the device interface. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Adaptive Security ApplianceCisco PIX Security ApplianceCisco Adaptive Security Appliance Software | 4/6/2008 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.1.x before 8.1(1)1 allows remote attackers to cause a denial of service (device reload) via a crafted Transport Layer Security (TLS) packet to the device interface. | |
| Modificada | Media (5.4) | 2.9% | — | Cisco PIX Security ApplianceCisco Adaptive Security Appliance Software | 4/6/2008 | 16/6/2026 | The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x before 8.1(1)2 allows remote attackers to cause a denial of service via a crafted packet. | |
| Modificada | Alta (7.8) | 2.5% | — | Cisco PIX Security ApplianceCisco Adaptive Security Appliance Software | 4/6/2008 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(3)2 and 8.0.x before 8.0(2)17 allows remote attackers to cause a denial of service (device reload) via a port scan against TCP port 443 on the device. | |
| Modificada | Alta (7.8) | 2.7% | — | Cisco PIX Security ApplianceCisco Adaptive Security Appliance Software | 4/6/2008 | 16/6/2026 | Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors. | |
| Modificada | Alta (7.1) | 2.0% | — | Cisco Adaptive Security Appliance SoftwareCisco PIX Firewall Software | 23/1/2008 | 16/6/2026 | Unspecified vulnerability in Cisco PIX 500 Series Security Appliance and 5500 Series Adaptive Security Appliance (ASA) before 7.2(3)6 and 8.0(3), when the Time-to-Live (TTL) decrement feature is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted IP packet. |