Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
587 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.7% | — | Cisco Webex Meeting CenterCisco Webex Meetings Server | 30/11/2017 | 17/6/2026 | A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (.arf) files could allow an attacker to execute arbitrary code on a system. An attacker could exploit this vulnerability by providing a user with a malicious .arf file via email or URL and convincing the user to… | |
| Modificada | Media (5) | 1.2% | — | Cisco Webex Meeting Center | 30/11/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directed to the Cisco WebEx Meeting Center. An attacker could exploit… | |
| Modificada | Media (5.8) | 2.2% | — | Cisco Meeting Server | 16/11/2017 | 17/6/2026 | A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server media process to restart unexpectedly when it receives an illegal H.264 frame. The vulnerability is triggered by an H.264 frame that has an invalid picture parameter set… | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Webex Meetings Server | 2/11/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. The vulnerability is due to the HTTP header reply from the Cisco… | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Webex Meetings Server | 2/11/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Alta (7.3) | 1.0% | — | Cisco Webex Meetings Server | 24/10/2017 | 17/6/2026 | Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643. | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Webex Meeting Center | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Webex Meetings Server | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An… | |
| Modificada | Alta (8.6) | 2.3% | — | Cisco Webex Meetings Server | 19/10/2017 | 17/6/2026 | A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient limitations on the number of connections that can be made to the affected software. An attacker could exploit this vulnerability by… | |
| Modificada | Media (5.5) | 0.36% | — | Cisco JabberCisco Webex Meeting Center | 19/10/2017 | 17/6/2026 | A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software.… | |
| Modificada | Crítica (9.8) | 4.8% | — | Apache Openmeetings | 12/10/2017 | 17/6/2026 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. | |
| Modificada | Media (4.2) | 0.36% | — | Cisco Meeting APP | 5/10/2017 | 17/6/2026 | A vulnerability in the routine that loads DLL files in Cisco Meeting App for Windows could allow an authenticated, local attacker to run an executable file with privileges equivalent to those of Cisco Meeting App. The vulnerability is due to incomplete input validation of the path name for DLL files before they are… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Meeting Server | 5/10/2017 | 17/6/2026 | A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient bound checks performed by the affected software. An attacker could exploit this vulnerability by sending a malicious… | |
| Modificada | Media (6.1) | 0.87% | — | Cisco Webex Meetings Server | 5/10/2017 | 17/6/2026 | A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to… | |
| Modificada | Crítica (9.1) | 3.1% | — | Cisco Meeting Server | 13/9/2017 | 17/6/2026 | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default… | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft Office 2007Microsoft Office 2010+5 | 13/9/2017 | 17/6/2026 | Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Add-in and Console allows an attacker to execute code remotely via… | |
| Modificada | Media (5.3) | 9.6% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office 2007+10 | 13/9/2017 | 17/6/2026 | Windows Uniscribe in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business 2016; Lync 2013 SP1; Lync… | |
| Modificada | Baja (3.3) | 14% | — | Microsoft Live MeetingMicrosoft LyncMicrosoft OfficeMicrosoft Office 2007+10 | 13/9/2017 | 17/6/2026 | The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, 1607, 1703, and Server 2016; Office 2007 SP3; Office 2010 SP2; Word Viewer; Office for Mac 2011 and 2016; Skype for Business… | |
| Modificada | Media (6.7) | 0.84% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient… | |
| Modificada | Media (6.5) | 1.5% | — | Cisco Meeting Server | 7/9/2017 | 17/6/2026 | A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to the incorrect implementation of the configuration setting… | |
| Modificada | Alta (7.5) | 2.3% | — | Cisco Meeting Server | 7/8/2017 | 17/6/2026 | A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability exists because the affected application does not properly validate Fragmentation Unit… | |
| Modificada | Alta (8.8) | 6.0% | — | Cisco Webex Event CenterCisco Webex Meeting CenterCisco Webex MeetingsCisco Webex Meetings Server+16 | 25/7/2017 | 17/6/2026 | A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco… | |
| Modificada | Alta (7.5) | 3.0% | — | Apache Openmeetings | 17/7/2017 | 17/6/2026 | Apache OpenMeetings 1.0.0 updates user password in insecure manner. | |
| Modificada | Media (5.3) | 2.9% | — | Apache Openmeetings | 17/7/2017 | 17/6/2026 | Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. | |
| Modificada | Alta (7.5) | 2.8% | — | Apache Openmeetings | 17/7/2017 | 17/6/2026 | Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by uploading multiple large files to the server. |