Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

60 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.99%💥 ExploitAVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+218/12/200616/6/2026
AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
ModificadaAlta (7.2)0.33%—AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+218/12/200616/6/2026
Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
ModificadaMedia (5)1.8%—Mcafee Internet Security SuiteMcafee Network AgentMcafee Personal Firewall PlusMcafee Virusscan20/10/200616/6/2026
McAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus, and VirusScan, allows remote attackers to cause a denial of service (agent crash) via a long packet, possibly because of an invalid string position field value. NOTE:…
ModificadaMedia (5)1.6%—Kerio Personal Firewall5/10/200616/6/2026
The (1) fwdrv.sys and (2) khips.sys drivers in Sunbelt Kerio Personal Firewall 4.3.268 and earlier do not validate arguments passed through to SSDT functions, including NtCreateFile, NtDeleteFile, NtLoadDriver, NtMapViewOfSection, NtOpenFile, and NtSetInformationFile, which allows local users to cause a denial of…
ModificadaMedia (4.9)1.3%💥 ExploitSymantec Client SecuritySymantec Host IDSSymantec Norton AntivirusSymantec Norton Internet Security+319/9/200616/6/2026
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5…
ModificadaBaja (3.6)0.35%—Symantec Norton Personal Firewall21/8/200616/6/2026
Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegRestoreKey to modify HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners, as demonstrated using NISProd.dll. NOTE:…
ModificadaMedia (6.8)34%💥 ExploitMcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+51/8/200616/6/2026
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands…
ModificadaBaja (2.1)0.71%💥 ExploitKerio Personal Firewall24/7/200616/6/2026
kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread.
ModificadaAlta (7.2)0.48%—Agnitum Outpost FirewallLavasoft Personal FirewallNovell Client Firewall21/7/200616/6/2026
Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and…
ModificadaBaja (2.1)0.40%—Symantec Norton Personal Firewall21/7/200616/6/2026
Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent registry keys.
ModificadaMedia (6.8)0.39%—Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+219/4/200616/6/2026
Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program.
ModificadaBaja (2.1)0.38%—Kerio Personal FirewallKerio Serverfirewall23/10/200516/6/2026
The FWDRV driver in Kerio Personal Firewall 4.2 and Server Firewall 1.1.1 allows local users to cause a denial of service (crash) by setting the PAGE_NOACCESS or PAGE_GUARD protection on the Page Environment Block (PEB), which triggers an exception, aka the "PEB lockout vulnerability."
ModificadaMedia (4.6)0.34%—Kerio Personal Firewall2/5/200516/6/2026
Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.
ModificadaAlta (7.5)2.6%—Kerio MailserverKerio Personal FirewallKerio Winroute Firewall2/5/200516/6/2026
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.
ModificadaMedia (5)1.6%—Kerio MailserverKerio Personal FirewallKerio Winroute Firewall29/4/200516/6/2026
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic…
ModificadaMedia (5)3.2%💥 ExploitKerio Personal Firewall10/1/200516/6/2026
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.
ModificadaBaja (2.6)6.7%💥 ExploitKerio Personal FirewallAI31/12/200416/6/2026
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of service (crash) by sending hex-encoded URLs containing "%13%12%13".
ModificadaAlta (7.2)0.56%—Kerio Personal Firewall31/12/200416/6/2026
Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configuration Files option, which does not drop privileges before opening the file loading dialog box.
ModificadaMedia (4.6)0.92%—Kerio Personal Firewall2/9/200416/6/2026
Kerio Personal Firewall 4.0 (KPF4) allows local users with administrative privileges to bypass the Application Security feature and execute arbitrary processes by directly writing to \device\physicalmemory to restore the running kernel's SDT ServiceTable.
ModificadaMedia (5)8.8%💥 ExploitSymantec Client FirewallSymantec Client SecuritySymantec Norton Internet SecuritySymantec Norton Personal Firewall18/8/200416/6/2026
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option…
ModificadaBaja (2.6)11%💥 ExploitSymantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+17/7/200416/6/2026
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop)…
ModificadaAlta (10)13%—Symantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+17/7/200416/6/2026
Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary…
ModificadaAlta (7.5)2.4%—Kerio Personal Firewall31/12/200316/6/2026
Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.
ModificadaAlta (7.5)3.8%—Kerio Personal Firewall 212/5/200316/6/2026
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server.
ModificadaAlta (7.5)69%💥 ExploitKerio Personal Firewall 212/5/200316/6/2026
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.
Orbitaley — Vulnerabilidades