Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.9%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
ModificadaMedia (4.3)2.2%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.
ModificadaMedia (4.3)1.1%—Anon Proxy Server20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Anon Proxy Server before 0.101 allow remote attackers to inject arbitrary web script or HTML via the URI, which is later displayed by (1) log.php or (2) logerror.php, a different vulnerability than CVE-2007-6459.
ModificadaMedia (6.8)2.9%—Anon Proxy Server20/12/200716/6/2026
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the host parameter to diagdns.php, and (2) the host parameter and possibly (3) the port parameter to diagconnect.php, a different vulnerability than CVE-2007-6460.
ModificadaAlta (10)26%—SUN Java System WEB Proxy Server29/5/200716/6/2026
Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.
ModificadaMedia (6.8)3.6%—SUN Java System Application ServerSUN Java System WEB Proxy ServerSUN Java System WEB ServerSUN ONE Application Server4/12/200616/6/2026
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified…
ModificadaMedia (4)1.1%—John Hanna Anti-spam Smtp Proxy Server21/8/200616/6/2026
Absolute path traversal vulnerability in the get functionality in Anti-Spam SMTP Proxy (ASSP) allows remote authenticated users to read arbitrary files via (1) C:\ (Windows drive letter), (2) UNC, and possibly other types of paths in the file parameter.
ModificadaMedia (5)2.5%—SUN Java System WEB Proxy Server31/12/200516/6/2026
Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.
ModificadaAlta (7.5)3.1%—SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server20/10/200516/6/2026
Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2…
ModificadaAlta (7.5)3.4%—SUN Java System WEB Proxy Server2/5/200516/6/2026
Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5)2.3%—Igor Khasilev Oops Proxy ServerGentoo Linux2/5/200516/6/2026
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
ModificadaAlta (7.5)17%—Microsoft ISA ServerMicrosoft Proxy ServerMicrosoft Windows 2003 Server27/1/200516/6/2026
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
ModificadaAlta (10)64%—Psoproxy Server23/11/200416/6/2026
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.
ModificadaAlta (7.5)7.7%—SUN Java System WEB Proxy Server30/10/200416/6/2026
Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.
ModificadaMedia (5)1.6%—IBM Websphere Caching Proxy ServerIBM Websphere Edge Server Caching Proxy6/8/200416/6/2026
WebSphere Edge Component Caching Proxy in WebSphere Edge Server 5.02, with the JunctionRewrite directive enabled, allows remote attackers to cause a denial of service via an HTTP GET request without any parameters.
ModificadaAlta (10)41%—Microsoft Proxy Server17/2/200416/6/2026
Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
ModificadaMedia (5)18%—Microsoft ISA ServerMicrosoft Proxy Server5/5/200316/6/2026
The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.
ModificadaMedia (6.8)3.3%—IBM Websphere Caching Proxy Server4/11/200216/6/2026
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP GET request.
ModificadaMedia (5)7.1%—IBM Websphere Caching Proxy Server4/11/200216/6/2026
IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to cause a denial of service (crash) via an HTTP request to helpout.exe with a missing HTTP version number, which causes ibmproxy.exe to crash.
ModificadaMedia (6.8)1.6%—IBM Websphere Caching Proxy Server4/11/200216/6/2026
Cross-site scripting (XSS) vulnerability in IBM Web Traffic Express Caching Proxy Server 3.6 and 4.x before 4.0.1.26 allows remote attackers to execute script as other users via an HTTP request that contains an Location: header with a "%0a%0d" (CRLF) sequence, which echoes the Location as an HTTP header in the server…
ModificadaAlta (7.5)54%—Microsoft Internet ExplorerMicrosoft ISA ServerMicrosoft Proxy ServerUniversity OF Minnesota Gopher3/7/200216/6/2026
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.
ModificadaAlta (10)2.2%—Netscape Enterprise ServerNetscape Fasttrack ServerNetscape Proxy ServerSCO Unixware12/3/200116/6/2026
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.
ModificadaAlta (10)7.1%—Igor Khasilev Oops Proxy Server12/2/200116/6/2026
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.