Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.9% | — | Cisco Content Switching ModuleCisco Content Switching Module SSL | 14/5/2008 | 16/6/2026 | Memory leak in Cisco Content Switching Module (CSM) 4.2(3) up to 4.2(8) and Cisco Content Switching Module with SSL (CSM-S) 2.1(2) up to 2.1(7) allows remote attackers to cause a denial of service (memory consumption) via TCP segments with an unspecified combination of TCP flags. | |
| Modificada | Alta (7.1) | 1.9% | — | Cisco Route Switch ProcessorCisco Supervisor Engine | 27/3/2008 | 16/6/2026 | Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device… | |
| Modificada | Baja (3.5) | 6.9% | — | Ipswitch ImserverIpswitch Instant Messaging | 25/2/2008 | 16/6/2026 | Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address… | |
| Modificada | Media (4.9) | 3.5% | — | Ipswitch ImserverIpswitch Instant Messaging | 25/2/2008 | 16/6/2026 | Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Ipswitch Instant Messaging | 25/2/2008 | 16/6/2026 | Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero. | |
| Modificada | Media (5) | 5.6% | — | Ipswitch WS FTP | 6/2/2008 | 16/6/2026 | The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different… | |
| Modificada | Alta (7.1) | 1.8% | — | APC OASAPC Switched Rack PDU Firmware | 4/12/2007 | 16/6/2026 | The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attackers to bypass authentication and obtain login access by making a login attempt while a different client is logged in, and then resubmitting the login attempt once the… | |
| Modificada | Alta (7.5) | 3.2% | — | Ipswitch Imail ClientIpswitch Imail Server | 31/10/2007 | 16/6/2026 | Buffer overflow in IMail Client 9.22, as shipped with IPSwitch IMail Server 2006.22, allows remote attackers to execute arbitrary code via a long boundary parameter in a multipart MIME e-mail message. | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Ipswitch Imail | 26/9/2007 | 16/6/2026 | Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in… | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Content Switching Module With SSLCisco Content Switching Modules | 10/9/2007 | 16/6/2026 | Cisco Content Switching Modules (CSM) 4.2 before 4.2.3a, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.2a, allow remote attackers to cause a denial of service (CPU consumption or reboot) via sets of out-of-order TCP packets with unspecified characteristics, aka CSCsd27478. | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Content Switching Module With SSLCisco Content Switching Modules | 10/9/2007 | 16/6/2026 | Cisco Content Switching Modules (CSM) 4.2 before 4.2.7, and Cisco Content Switching Module with SSL (CSM-S) 2.1 before 2.1.6, when service termination is enabled, allow remote attackers to cause a denial of service (reboot) via unspecified vectors related to high network utilization, aka CSCsh57876. | |
| Modificada | Media (4.3) | 1.6% | — | Ipswitch WS FTP | 28/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Ipswitch WS_FTP allows remote attackers to inject arbitrary web script or HTML via arguments to a valid command, which is not properly handled when it is displayed by the view log option in the administration interface. NOTE: this can be leveraged to create a new admin… | |
| Modificada | Media (5) | 6.5% | — | Ipswitch ImserverIpswitch Collaboration Suite | 24/7/2007 | 16/6/2026 | The IM Server (aka IMserve or IMserver) 2.0.5.30 and probably earlier in Ipswitch Instant Messaging before 2.07 in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (daemon crash) via certain data to TCP port 5179 that overwrites a destructor, as reachable by the (1)… | |
| Modificada | Media (6.5) | 85% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command. | |
| Modificada | Alta (7.8) | 2.9% | — | Ipswitch Imail Server | 21/7/2007 | 16/6/2026 | Ipswitch IMail Server 2006 before 2006.21 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving an "overwritten destructor." | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Ipswitch Imail ServerIpswitch Collaboration Suite | 21/7/2007 | 16/6/2026 | Multiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors in Imailsec and (2) allow attackers to have an unknown impact via an unspecified vector related to "subscribe." | |
| Modificada | Alta (7.8) | 25% | — | Ipswitch WS FTP | 17/7/2007 | 16/6/2026 | The Logging Server (Logsrv.exe) in IPSwitch WS_FTP 7.5.29.0 allows remote attackers to cause a denial of service (daemon crash) by sending a crafted packet containing a long string to port 5151/udp. | |
| Modificada | Alta (7.8) | 3.2% | — | HP Procurve Switch 9300m | 4/5/2007 | 16/6/2026 | Unspecified vulnerability in HP ProCurve 9300m Series switches with software 08.0.01c through 08.0.01j allows remote attackers to cause a denial of service via unknown vectors, a different switch series than CVE-2006-4015. | |
| Modificada | Alta (7.8) | 4.6% | — | Ipswitch WS FTP | 24/4/2007 | 16/6/2026 | Unspecified vulnerability in the Initialize function in NetscapeFTPHandler in WS_FTP Home and Professional 2007 allows remote attackers to cause a denial of service (NULL dereference and application crash) via unspecified vectors related to "improper arguments." | |
| Modificada | Alta (9.3) | 5.6% | — | Ipswitch ImailIpswitch Imail PlusIpswitch Imail PremiumIpswitch Collaboration Suite | 23/3/2007 | 16/6/2026 | Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the… | |
| Modificada | Media (6.8) | 3.3% | — | Ipswitch WS FTP PRO | 2/2/2007 | 16/6/2026 | Format string vulnerability in the SCP module in Ipswitch WS_FTP 2007 Professional might allow remote attackers to execute arbitrary commands via format string specifiers in the filename, related to the SHELL WS_FTP script command. | |
| Modificada | Media (6.8) | 1.9% | — | Ipswitch WS FTP Server | 2/2/2007 | 16/6/2026 | Ipswitch WS_FTP Server 5.04 allows FTP site administrators to execute arbitrary code on the system via a long input string to the (1) iFTPAddU or (2) iFTPAddH file, or to a (3) edition module. | |
| Modificada | Alta (7.5) | 3.4% | — | Ipswitch WS FTP PRO | 18/1/2007 | 16/6/2026 | Buffer overflow in wsbho2k0.dll, as used by wsftpurl.exe, in Ipswitch WS_FTP 2007 Professional allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long ftp:// URL in an HTML document, and possibly other vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Alliedtelesyn At-9000 24 Ethernetswitch | 23/12/2006 | 16/6/2026 | The Allied Telesis AT-9000/24 Ethernet switch accepts management packets from arbitrary VLANs, contrary to the documentation, which allows remote attackers to conduct attacks against the switch from unexpected locations. | |
| Modificada | Alta (7.5) | 1.3% | — | Alliedtelesyn At-9000 24 Ethernetswitch | 23/12/2006 | 16/6/2026 | The Allied Telesis AT-9000/24 Ethernet switch has a default password for its admin account, "manager," which allows remote attackers to perform unauthorized actions. |