Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

640 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.3%—Eset Nod32 Antivirus11/12/200816/6/2026
ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail…
ModificadaAlta (9.3)11%💥 ExploitBitdefender AntivirusBitdefenderBullguard Internet SecuritySoftware602 Groupware Server10/12/200816/6/2026
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted…
ModificadaAlta (7.5)3.0%—Havp Http Antivirus Proxy14/8/200816/6/2026
sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.
ModificadaMedia (5)7.9%💥 ExploitF-prot AntivirusF-prot Scanning Engine4/8/200816/6/2026
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.
ModificadaMedia (5)2.6%—Grisoft AVG Antivirus30/7/200816/6/2026
The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted UPX compressed file, which triggers a divide-by-zero error.
ModificadaMedia (4.3)2.1%—F-prot AntivirusF-prot Scanning Engine21/7/200816/6/2026
Multiple unspecified vulnerabilities in the scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allow remote attackers to cause a denial of service via (1) a crafted UPX-compressed file, which triggers an engine crash; (2) a crafted Microsoft Office file, which triggers an infinite loop; or (3) an…
ModificadaMedia (4.3)2.2%—F-prot AntivirusF-prot Scanning Engine21/7/200816/6/2026
The scanning engine before 4.4.4 in F-Prot Antivirus before 6.0.9.0 allows remote attackers to cause a denial of service (engine crash) via a CHM file with a large nb_dir value that triggers an out-of-bounds read.
ModificadaBaja (2.1)0.87%—Rising-global Rising Antivirus30/4/200816/6/2026
Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid pointer to the _CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.
ModificadaMedia (4.9)0.37%—Bitdefender Antivirus30/4/200816/6/2026
BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an invalid pointer to the CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.
ModificadaMedia (6.8)4.0%—Symantec Norton 360Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec System Works8/4/200816/6/2026
The ActiveDataInfo.LaunchProcess method in the SymAData.ActiveDataInfo.1 ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, does not properly determine the location…
ModificadaAlta (9.3)6.1%—Symantec Norton 360Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works8/4/200816/6/2026
Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through 2008, allows remote attackers to execute arbitrary code via a…
ModificadaMedia (6.8)0.71%💥 ExploitAvast Antivirus HomeAvast Antivirus Professional2/4/200816/6/2026
aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.
ModificadaAlta (7.2)1.1%💥 ExploitPanda Antivirus AND FirewallPanda Internet Security24/3/200816/6/2026
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.
ModificadaMedia (6.8)3.6%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+820/3/200816/6/2026
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as…
ModificadaAlta (10)15%💥 ExploitKingsoft Antivirus Online Update Module12/3/200816/6/2026
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method.
ModificadaAlta (9.3)10%💥 ExploitRising Antivirus International Rising WEB Scan Object3/3/200816/6/2026
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third…
ModificadaMedia (6.8)3.7%—Symantec Scan EngineSymantec Antivirus Filtering Domino MPESymantec Antivirus Network Attached StorageSymantec Antivirus Scan Engine+628/2/200816/6/2026
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content…
ModificadaAlta (7.1)2.6%—Symantec Scan EngineSymantec Antivirus ClearswiftSymantec Antivirus Filtering Domino MPESymantec Antivirus Messaging+628/2/200816/6/2026
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
ModificadaAlta (7.5)4.0%—Kerio MailserverVisnetic Antivirus Plug-in FOR Mail Server21/2/200816/6/2026
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)31%💥 ExploitComodo AntivirusMicrosoft Activex29/1/200816/6/2026
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.
ModificadaAlta (7.2)1.0%—Trend Micro Antivirus Plus AntispywareTrend Micro Internet Security Virus BustTrend Micro Internet Security PRO15/12/200716/6/2026
Stack-based buffer overflow in PccScan.dll before build 1451 in Trend Micro AntiVirus plus AntiSpyware 2008, Internet Security 2008, and Internet Security Pro 2008 allows user-assisted remote attackers to cause a denial of service (SfCtlCom.exe crash), and allows local users to gain privileges, via a malformed .zip…
ModificadaMedia (6.8)1.3%—Avast Antivirus HomeAvast Antivirus Professional7/12/200716/6/2026
Unspecified vulnerability in avast! 4 Home and Professional Editions before 4.7.1098 allows remote attackers to have an unknown impact via a crafted TAR archive.
ModificadaMedia (6)0.31%—Symantec Norton AntivirusSymantec Norton Internet Security5/11/200716/6/2026
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which…
ModificadaCrítica (9.8)27%💥 ExploitBitdefender AntivirusBitdefender Internet SecurityBitdefender Total Security1/11/200716/6/2026
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for…
ModificadaAlta (7.6)5.0%—Gdata Antivirus13/10/200716/6/2026
Buffer overflow in a certain ActiveX control in ScanObjectBrowser.DLL in G DATA Antivirus 2007 might allow remote attackers to execute arbitrary code via unspecified parameters to the SelectPath function. NOTE: this issue might not cross privilege boundaries in most environments, since it is not marked as safe for…
Orbitaley — Vulnerabilidades