Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

552 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)15%—Apache Http Server3/11/200416/6/2026
The mod_ssl module in Apache 2.0.35 through 2.0.52, when using the "SSLCipherSuite" directive in directory or location context, allows remote clients to bypass intended restrictions by using any cipher suite that is allowed by the virtual host configuration.
ModificadaMedia (5)24%—Apache Http Server20/10/200416/6/2026
The IPv6 URI parsing routines in the apr-util library for Apache 2.0.50 and earlier allow remote attackers to cause a denial of service (child process crash) via a certain URI, as demonstrated using the Codenomicon HTTP Test Tool.
ModificadaAlta (7.8)1.6%—Apache Http Server20/10/200416/6/2026
Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.
ModificadaMedia (5)72%💥 ExploitApache Http Server20/10/200416/6/2026
The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).
ModificadaMedia (5)25%—Apache Http Server20/10/200416/6/2026
mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.
ModificadaMedia (5)17%—Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+816/9/200416/6/2026
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
ModificadaMedia (6.4)85%💥 ExploitAvaya Converged Communications ServerGentoo LinuxTrustix Secure LinuxApache Http Server+46/8/200416/6/2026
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
ModificadaAlta (10)34%—Apache Http ServerHP VirtualvaultHP WebproxyIBM Http Server+36/8/200416/6/2026
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
ModificadaAlta (7.5)38%—Apache Http ServerDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation7/7/200416/6/2026
Stack-based buffer overflow in the ssl_util_uuencode_binary function in ssl_util.c for Apache mod_ssl, when mod_ssl is configured to trust the issuing CA, may allow remote attackers to execute arbitrary code via a client certificate with a long subject DN.
ModificadaMedia (5)3.8%💥 ExploitMinishare Minimal Http Server26/5/200416/6/2026
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
ModificadaAlta (7.5)12%—Apache Http Server4/5/200416/6/2026
Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."
ModificadaMedia (5)16%💥 ExploitApache Http Server15/4/200416/6/2026
Directory traversal vulnerability in Apache 1.3.29 and earlier, and Apache 2.0.48 and earlier, when running on Cygwin, allows remote attackers to read arbitrary files via a URL containing "..%5C" (dot dot encoded backslash) sequences.
ModificadaBaja (2.6)3.0%—Oracle Application ServerOracle Http Server30/3/200416/6/2026
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
ModificadaAlta (7.5)11%—Apache Http Server29/3/200416/6/2026
mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.
ModificadaMedia (5)11%—Apache Http Server29/3/200416/6/2026
Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.
ModificadaBaja (2.1)3.5%—Apache Http Server20/3/200416/6/2026
mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information.
ModificadaAlta (7.5)5.6%—Apache Http Server3/3/200416/6/2026
mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.
ModificadaAlta (7.5)7.6%—Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+103/2/200416/6/2026
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
ModificadaMedia (4.3)2.0%—Bajie Java Http Server31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message.
ModificadaMedia (4.3)1.7%💥 ExploitApache Http Server31/12/200316/6/2026
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has…
ModificadaMedia (4.3)3.6%💥 ExploitBajie Java Http Server31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet.
ModificadaMedia (4.3)6.6%—Apache Http Server31/12/200316/6/2026
Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID).
ModificadaAlta (7.2)30%—Apache Http Server3/11/200316/6/2026
Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.
ModificadaAlta (10)12%—Apache Http Server3/11/200316/6/2026
mod_cgid in Apache before 2.0.48, when using a threaded MPM, does not properly handle CGI redirect paths, which could cause Apache to send the output of a CGI program to the wrong client.
ModificadaMedia (5)13%—Apache Http Server27/8/200316/6/2026
The rotatelogs program on Apache before 1.3.28, for Windows and OS/2 systems, does not properly ignore certain control characters that are received over the pipe, which could allow remote attackers to cause a denial of service.