Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 57% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+9 | 20/6/2017 | 17/6/2026 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force… | |
| Modificada | Crítica (9.8) | 20% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+10 | 20/6/2017 | 17/6/2026 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. | |
| Modificada | Crítica (9.6) | 1.7% | — | Oracle Secure Global Desktop | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services. | |
| Modificada | Crítica (9.8) | 5.5% | — | Oracle Secure Global Desktop | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, and 5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to OpenSSL. | |
| Modificada | Media (5) | 1.9% | — | Oracle Secure Global Desktop | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.2 allows remote attackers to affect availability via vectors related to SGD Core. | |
| Modificada | Media (6.8) | 86% | 💥 Exploit | Apache Http ServerDebian LinuxRedhat Jboss Enterprise Application PlatformOracle Enterprise Manager OPS Center+2 | 20/7/2014 | 17/6/2026 | Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denial of service (heap-based buffer overflow), or possibly obtain sensitive credential information or execute arbitrary code, via a crafted request that triggers improper scoreboard handling within the… | |
| Modificada | Media (4.3) | 2.1% | — | Oracle VirtualizationOracle Virtualization Secure Global Desktop | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-2463. | |
| Modificada | Media (5) | 27% | — | Apache Http ServerOracle Http ServerOracle Secure Global DesktopCanonical Ubuntu Linux | 18/3/2014 | 17/6/2026 | The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server before 2.4.8 allows remote attackers to cause a denial of service (segmentation fault and daemon crash) via a crafted cookie that is not properly handled during truncation. | |
| Modificada | Media (5.1) | 1.5% | — | Oracle Virtualization Secure Global Desktop | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization SGD before 4.63 with December 2013 PSU, 4.71, 5.0 with December 2013 PSU, and 5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console… | |
| Modificada | Media (6.8) | 2.5% | — | Debian LinuxOracle Secure Global DesktopCanonical Ubuntu LinuxOpensuse+2 | 15/6/2013 | 16/6/2026 | Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function. | |
| Modificada | Media (4) | 3.4% | — | SUN NSSSUN Secure Global DesktopSUN StarofficeSUN Solaris+5 | 10/10/2006 | 16/6/2026 | Multiple packages on Sun Solaris, including (1) NSS; (2) Java JDK and JRE 5.0 Update 8 and earlier, SDK and JRE 1.4.x up to 1.4.2_12, and SDK and JRE 1.3.x up to 1.3.1_19; (3) JSSE 1.0.3_03 and earlier; (4) IPSec/IKE; (5) Secure Global Desktop; and (6) StarOffice, when using an RSA key with exponent 3, removes PKCS-1… | |
| Modificada | Media (5) | 1.7% | — | SUN Secure Global Desktop | 23/9/2006 | 16/6/2026 | Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, including hostnames, versions, and settings details, via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5) ttawebtop.cgi,… | |
| Modificada | Media (6.8) | 3.0% | — | SUN Secure Global Desktop | 23/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving (1) taarchives.cgi, (2) ttaAuthentication.jsp, (3) ttalicense.cgi, (4) ttawlogin.cgi, (5)… | |
| Modificada | Media (5) | 1.3% | — | Tarantella Secure Global DesktopTarantella Enterprise | 30/3/2005 | 16/6/2026 | Tarantella Secure Global Desktop Enterprise Edition 4.00 and 3.42, and Tarantella Enterprise 3 3.40 and 3.30, when using RSA SecurID and multiple users have the same username, reveals sensitive information during authentication, which allows remote attackers to identify valid usernames and the authentication scheme. |