Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.3% | — | Eset Nod32 Antivirus | 11/12/2008 | 16/6/2026 | ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail… | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Bitdefender AntivirusBitdefenderBullguard Internet SecuritySoftware602 Groupware Server | 10/12/2008 | 16/6/2026 | Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted… | |
| Modificada | Alta (7.5) | 3.0% | — | Havp Http Antivirus Proxy | 14/8/2008 | 16/6/2026 | sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | F-prot AntivirusF-prot Scanning Engine | 4/8/2008 | 16/6/2026 | The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets. | |
| Modificada | Media (5) | 2.6% | — | Grisoft AVG Antivirus | 30/7/2008 | 16/6/2026 | The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted UPX compressed file, which triggers a divide-by-zero error. | |
| Modificada | Media (4.3) | 2.1% | — | F-prot AntivirusF-prot Scanning Engine | 21/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an… | |
| Modificada | Media (4.3) | 2.2% | — | F-prot AntivirusF-prot Scanning Engine | 21/7/2008 | 16/6/2026 | The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read. | |
| Modificada | Baja (2.1) | 0.87% | — | Rising-global Rising Antivirus | 30/4/2008 | 16/6/2026 | Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid pointer to the _CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function. | |
| Modificada | Media (4.9) | 0.37% | — | Bitdefender Antivirus | 30/4/2008 | 16/6/2026 | BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an invalid pointer to the CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function. | |
| Modificada | Media (6.8) | 4.0% | — | Symantec Norton 360Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec System Works | 8/4/2008 | 16/6/2026 | The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location… | |
| Modificada | Alta (9.3) | 6.1% | — | Symantec Norton 360Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 8/4/2008 | 16/6/2026 | Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a… | |
| Modificada | Media (6.8) | 0.71% | 💥 Exploit | Avast Antivirus HomeAvast Antivirus Professional | 2/4/2008 | 16/6/2026 | aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Panda Antivirus AND FirewallPanda Internet Security | 24/3/2008 | 16/6/2026 | The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory. | |
| Modificada | Media (6.8) | 3.6% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+8 | 20/3/2008 | 16/6/2026 | Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as… | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Kingsoft Antivirus Online Update Module | 12/3/2008 | 16/6/2026 | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Rising Antivirus International Rising WEB Scan Object | 3/3/2008 | 16/6/2026 | Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third… | |
| Modificada | Media (6.8) | 3.7% | — | Symantec Scan EngineSymantec Antivirus Filtering Domino MPESymantec Antivirus Network Attached StorageSymantec Antivirus Scan Engine+6 | 28/2/2008 | 16/6/2026 | Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content… | |
| Modificada | Alta (7.1) | 2.6% | — | Symantec Scan EngineSymantec Antivirus ClearswiftSymantec Antivirus Filtering Domino MPESymantec Antivirus Messaging+6 | 28/2/2008 | 16/6/2026 | Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp). | |
| Modificada | Alta (7.5) | 4.0% | — | Kerio MailserverVisnetic Antivirus Plug-in FOR Mail Server | 21/2/2008 | 16/6/2026 | Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Comodo AntivirusMicrosoft Activex | 29/1/2008 | 16/6/2026 | A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method. | |
| Modificada | Alta (7.2) | 1.0% | — | Trend Micro Antivirus Plus AntispywareTrend Micro Internet Security Virus BustTrend Micro Internet Security PRO | 15/12/2007 | 16/6/2026 | Stack-based buffer overflow in PccScan.dll before build 1451 in Trend Micro AntiVirus plus AntiSpyware 2008, Internet Security 2008, and Internet Security Pro 2008 allows user-assisted remote attackers to cause a denial of service (SfCtlCom.exe crash), and allows local users to gain privileges, via a malformed .zip… | |
| Modificada | Media (6.8) | 1.3% | — | Avast Antivirus HomeAvast Antivirus Professional | 7/12/2007 | 16/6/2026 | Unspecified vulnerability in avast! 4 Home and Professional Editions before 4.7.1098 allows remote attackers to have an unknown impact via a crafted TAR archive. | |
| Modificada | Media (6) | 0.31% | — | Symantec Norton AntivirusSymantec Norton Internet Security | 5/11/2007 | 16/6/2026 | The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which… | |
| Modificada | Crítica (9.8) | 27% | 💥 Exploit | Bitdefender AntivirusBitdefender Internet SecurityBitdefender Total Security | 1/11/2007 | 16/6/2026 | Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for… | |
| Modificada | Alta (7.6) | 5.0% | — | Gdata Antivirus | 13/10/2007 | 16/6/2026 | Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. NOTE: this issue might not cross privilege boundaries in most environments, since it is not marked as safe for… |