Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
640 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.46% | — | Virusblokada Vba32 Antivirus | 6/10/2007 | 16/6/2026 | VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privileges by replacing application programs, as demonstrated by replacing vba32ldr.exe. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Media (6.8) | 4.0% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 9/8/2007 | 16/6/2026 | Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly… | |
| Modificada | Media (6.9) | 0.76% | 💥 Exploit | Panda Antivirus | 8/8/2007 | 16/6/2026 | Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657. | |
| Modificada | Media (4.3) | 3.6% | — | Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+19 | 26/7/2007 | 16/6/2026 | arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file. | |
| Modificada | Media (5) | 3.2% | — | Eset Software Nod32 Antivirus | 25/7/2007 | 16/6/2026 | Integer overflow in ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted ASPACK packed file, which triggers an infinite loop. | |
| Modificada | Alta (9.3) | 5.7% | — | Panda Antivirus | 25/7/2007 | 16/6/2026 | Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from an "Integer Cast Around." | |
| Modificada | Media (5) | 3.2% | — | Eset Software Nod32 Antivirus | 25/7/2007 | 16/6/2026 | ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error. | |
| Modificada | Alta (7.6) | 5.6% | — | Eset Nod32 Antivirus | 25/7/2007 | 16/6/2026 | Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption. | |
| Modificada | Alta (7.5) | 5.3% | — | Norman Normon Antivirus | 24/7/2007 | 16/6/2026 | The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an "integer cast around". | |
| Modificada | Media (6) | 0.31% | — | Symantec Client SecuritySymantec Norton Antivirus | 16/7/2007 | 16/6/2026 | Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code. | |
| Modificada | Media (4.6) | 0.36% | — | Symantec Client SecuritySymantec Norton Antivirus | 15/7/2007 | 16/6/2026 | Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the… | |
| Modificada | Alta (7.2) | 0.35% | — | Grisoft AVG Antivirus | 15/7/2007 | 16/6/2026 | avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges via arbitrary address arguments to a function provided by the 0x5348E004 IOCTL for the generic DeviceIoControl handler. | |
| Modificada | Media (6.9) | 1.1% | 💥 Exploit | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 15/7/2007 | 16/6/2026 | Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt… | |
| Modificada | Alta (9) | 2.2% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 6/6/2007 | 16/6/2026 | Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown… | |
| Modificada | Alta (9.3) | 50% | 💥 Exploit | Broadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+9 | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file. | |
| Modificada | Alta (7.5) | 2.0% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations… | |
| Modificada | Media (4.3) | 2.1% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute… | |
| Modificada | Alta (10) | 7.5% | — | Avira AntivirAvira AV Pack | 1/6/2007 | 16/6/2026 | Buffer overflow in the file parsing engine in Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to execute arbitrary code via a crafted LZH archive file, resulting from an "integer cast around." | |
| Modificada | Alta (7.8) | 3.4% | — | Avira AntivirAvira AV Pack | 1/6/2007 | 16/6/2026 | Avira Antivir Antivirus before 7.03.00.09 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed TAR archive. | |
| Modificada | Alta (7.8) | 3.4% | — | Avira AntivirAvira AV Pack | 1/6/2007 | 16/6/2026 | The file parsing engine in Avira Antivir Antivirus before 7.04.00.24 allows remote attackers to cause a denial of service (application crash) via a crafted UPX compressed file, which triggers a divide-by-zero error. | |
| Modificada | Alta (9.3) | 6.6% | — | Authentium Command Antivirus | 1/6/2007 | 16/6/2026 | Multiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 6.5% | — | Eset Software Nod32 Antivirus | 24/5/2007 | 16/6/2026 | Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name. | |
| Modificada | Alta (9.3) | 6.3% | — | Avast Antivirus | 24/5/2007 | 16/6/2026 | Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB archive, resulting from an "integer cast around". |