Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 91% | 💥 Exploit | Apache Http ServerApache Tomcat | 16/3/2007 | 16/6/2026 | Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3)… | |
| Modificada | Media (6.8) | 1.6% | — | Jetty Http Server | 7/2/2007 | 16/6/2026 | Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication requirements, and possibly conduct cross-site… | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Karjasoft Sami Http Server | 29/1/2007 | 16/6/2026 | KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number of requests for nonexistent objects. | |
| Modificada | Alta (7.5) | 2.5% | — | Oracle E-business SuiteOracle Http Server | 17/1/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle HTTP Server 9.2.0.8 and Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, aka (1) OHS01, (2) OHS02, (3) OHS05, (4) OHS06, and (5) OHS07. | |
| Modificada | Media (5) | 1.7% | — | Oracle Application ServerOracle Collaboration SuiteOracle Http Server | 17/1/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1)… | |
| Modificada | Alta (7.5) | 3.2% | — | Oracle Application ServerOracle Collaboration SuiteOracle Http Server | 17/1/2007 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not… | |
| Modificada | Baja (3.2) | 0.42% | — | Oracle Application ServerOracle Collaboration SuiteOracle Http Server | 17/1/2007 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN02. | |
| Modificada | Alta (7.8) | 10% | — | Apache Http Server | 5/1/2007 | 16/6/2026 | The Apache HTTP Server, when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same fragment. NOTE: the severity of this issue has been disputed by third parties, who… | |
| Modificada | Media (6.8) | 2.0% | — | Novell Apache Http ServerNovell Netware | 21/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Novell NetWare 6.5 Support Pack 5 and 6 and Novell Apache on NetWare 2.0.48 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters in Welcome web-app. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Collaboration SuiteOracle E-business SuiteOracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle Collaboration Suite 9.0.4.2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS04. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Application ServerOracle Collaboration SuiteOracle E-business SuiteOracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06. | |
| Modificada | Alta (7.6) | 2.3% | — | Oracle Collaboration SuiteOracle E-business SuiteOracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4.2 and Oracle E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors related to htdigest, aka Vuln# OHS02. | |
| Modificada | Alta (7.2) | 0.54% | — | Oracle E-business SuiteOracle Http Server | 18/10/2006 | 16/6/2026 | Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and local attack vectors, aka Vuln# OHS08. | |
| Modificada | Media (6.8) | 16% | — | Apache Http Server | 16/10/2006 | 16/6/2026 | Format string vulnerability in the mod_tcl module 1.0 for Apache 2.x allows context-dependent attackers to execute arbitrary code via format string specifiers that are not properly handled in a set_var function call in (1) tcl_cmds.c and (2) tcl_core.c. | |
| Modificada | Media (4.3) | 40% | 💥 Exploit | Apache Http Server | 14/8/2006 | 16/6/2026 | Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems. | |
| Modificada | Alta (7.6) | 97% | 💥 Exploit | Apache Http ServerCanonical Ubuntu LinuxDebian Linux | 28/7/2006 | 16/6/2026 | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that… | |
| Modificada | Media (4.3) | 95% | 💥 Exploit | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Server+1 | 28/7/2006 | 16/6/2026 | http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS)… | |
| Modificada | Alta (7.8) | 2.3% | — | Gnome Dwarf Http Server | 13/3/2006 | 16/6/2026 | Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request. | |
| Modificada | Media (4.3) | 1.4% | — | Gnome Dwarf Http Server | 13/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages. | |
| Modificada | Alta (7.5) | 6.8% | — | Oracle Application ServerOracle Http Server | 26/1/2006 | 16/6/2026 | Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the… | |
| Modificada | Alta (10) | 13% | — | HP Http Server | 31/12/2005 | 16/6/2026 | Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5.4) | 24% | — | Apache Http Server | 31/12/2005 | 16/6/2026 | mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference. | |
| Modificada | Media (4.3) | 74% | — | Apache Http Server | 13/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps. |