Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

629 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)4.0%—Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works9/8/200716/6/2026
Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly…
ModificadaMedia (6.9)0.76%💥 ExploitPanda Antivirus8/8/200716/6/2026
Panda Antivirus 2008 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying PAVSRV51.EXE or other unspecified files, a related issue to CVE-2006-4657.
ModificadaMedia (4.3)3.6%—Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+1926/7/200716/6/2026
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
ModificadaMedia (5)3.2%—Eset Software Nod32 Antivirus25/7/200716/6/2026
ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service via a crafted (1) ASPACK or (2) FSG packed file, which triggers a divide-by-zero error.
ModificadaAlta (9.3)5.7%—Panda Antivirus25/7/200716/6/2026
Buffer overflow in Panda Antivirus before 20070720 allows remote attackers to execute arbitrary code via a crafted EXE file, resulting from an "Integer Cast Around."
ModificadaMedia (5)3.2%—Eset Software Nod32 Antivirus25/7/200716/6/2026
Integer overflow in ESET NOD32 Antivirus before 2.2289 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted ASPACK packed file, which triggers an infinite loop.
ModificadaAlta (7.6)5.6%—Eset Nod32 Antivirus25/7/200716/6/2026
Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap corruption.
ModificadaAlta (7.5)5.3%—Norman Normon Antivirus24/7/200716/6/2026
The OLE2 parsing in Norman Antivirus before 5.91.02 allows remote attackers to bypass the malware detection via a crafted DOC file, resulting from an "integer cast around".
ModificadaMedia (6)0.31%—Symantec Client SecuritySymantec Norton Antivirus16/7/200716/6/2026
Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code.
ModificadaMedia (4.6)0.36%—Symantec Client SecuritySymantec Norton Antivirus15/7/200716/6/2026
Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the…
ModificadaAlta (7.2)0.35%—Grisoft AVG Antivirus15/7/200716/6/2026
avg7core.sys 7.5.0.444 in Grisoft AVG Anti-Virus 7.5.448 and Free Edition 7.5.446, provides an internal function that copies data to an arbitrary address, which allows local users to gain privileges via arbitrary address arguments to a function provided by the 0x5348E004 IOCTL for the generic DeviceIoControl handler.
ModificadaMedia (6.9)1.1%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+215/7/200716/6/2026
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt…
ModificadaAlta (9)2.2%—Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server6/6/200716/6/2026
Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown…
ModificadaAlta (9.3)50%💥 ExploitBroadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+96/6/200716/6/2026
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.
ModificadaAlta (7.5)2.0%—Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server5/6/200716/6/2026
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations…
ModificadaMedia (4.3)2.1%—Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server5/6/200716/6/2026
Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute…
ModificadaAlta (9.3)6.6%—Authentium Command Antivirus1/6/200716/6/2026
Multiple buffer overflows in a certain ActiveX control in odapi.dll in Authentium Command Antivirus before 4.93.8 allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)6.5%—Eset Software Nod32 Antivirus24/5/200716/6/2026
Multiple stack-based buffer overflows in ESET NOD32 Antivirus before 2.70.37.0 allow remote attackers to execute arbitrary code during (1) delete/disinfect or (2) rename operations via a crafted directory name.
ModificadaAlta (9.3)7.7%—Avas!t Avast! AntivirusAvast! Antivirus24/5/200716/6/2026
Heap-based buffer overflow in the SIS unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted SIS archive, resulting from an "integer cast around."
ModificadaAlta (9.3)6.3%—Avast Antivirus24/5/200716/6/2026
Heap-based buffer overflow in the CAB unpacker in avast! Anti-Virus Managed Client before 4.7.700 allows user-assisted remote attackers to execute arbitrary code via a crafted CAB archive, resulting from an "integer cast around".
ModificadaAlta (8.5)3.9%—Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works11/5/200716/6/2026
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors…
ModificadaAlta (7.8)3.2%—AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+99/5/200716/6/2026
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaAlta (7.8)3.2%—Avast Antivirus9/5/200716/6/2026
avast! antivirus before 4.7.981 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaAlta (7.8)3.0%—Panda ActivescanPanda AntivirusPanda Platinum 2006 Internet SecurityPanda Platinum 2007 Internet Security+29/5/200716/6/2026
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaMedia (4.9)1.7%💥 ExploitSymantec AntivirusSymantec Client SecuritySymantec Norton 360Symantec Norton Antispam+42/4/200716/6/2026
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2)…
Orbitaley — Vulnerabilidades