Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
629 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.5% | — | Trend Micro Antivirus | 22/3/2007 | 16/6/2026 | VsapiNT.sys in the Scan Engine 8.0 for Trend Micro AntiVirus 14.10.1041, and other products, allows remote attackers to cause a denial of service (kernel fault and system crash) via a crafted UPX file with a certain field that triggers a divide-by-zero error. | |
| Modificada | Baja (1.9) | 0.86% | 💥 Exploit | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 16/3/2007 | 16/6/2026 | The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's… | |
| Modificada | Alta (7.8) | 3.0% | — | Kaspersky LAB Kaspersky Antivirus Engine | 6/3/2007 | 16/6/2026 | Kaspersky AntiVirus Engine 6.0.1.411 for Windows and 5.5-10 for Linux allows remote attackers to cause a denial of service (CPU consumption) via a crafted UPX compressed file with a negative offset, which triggers an infinite loop during decompression. | |
| Modificada | Alta (10) | 10% | — | Supportsoft ScriptrunnerSupportsoft SmartissueSymantec Automated Support AssistantSymantec Norton Antivirus+2 | 22/2/2007 | 16/6/2026 | Multiple buffer overflows in the SupportSoft (1) SmartIssue (tgctlsi.dll) and (2) ScriptRunner (tgctlsr.dll) ActiveX controls, as used by Symantec Automated Support Assistant and Norton AntiVirus, Internet Security, and System Works 2006, allows remote attackers to execute arbitrary code via a crafted HTML message. | |
| Modificada | Alta (7.2) | 0.95% | — | Trend Micro Client-server-messaging SecurityTrend Micro Damage Cleanup ServicesTrend Micro Pc-cillin Internet SecurityTrend Micro Tmcomm.sys+4 | 8/2/2007 | 16/6/2026 | TmComm.sys 1.5.0.1052 in the Trend Micro Anti-Rootkit Common Module (RCM), with the VsapiNI.sys 3.320.0.1003 scan engine, as used in Trend Micro PC-cillin Internet Security 2007, Antivirus 2007, Anti-Spyware for SMB 3.2 SP1, Anti-Spyware for Consumer 3.5, Anti-Spyware for Enterprise 3.0 SP2, Client / Server /… | |
| Modificada | Media (4.4) | 0.34% | — | Alwil Avast Antivirus | 7/2/2007 | 16/6/2026 | avast! Server Edition before 4.7.726 does not demand a password in a certain intended context, even when a password has been set, which allows local users to bypass authentication requirements. | |
| Modificada | Media (5) | 2.7% | — | Kaspersky LAB Kaspersky Antivirus Engine | 9/1/2007 | 16/6/2026 | Kaspersky Labs Antivirus Engine 6.0 for Windows and 5.5-10 for Linux before 20070102 enter an infinite loop upon encountering an invalid NumberOfRvaAndSizes value in the Optional Windows Header of a portable executable (PE) file, which allows remote attackers to cause a denial of service (CPU consumption) by scanning… | |
| Modificada | Baja (2.6) | 2.2% | — | Eset Software Nod32 Antivirus | 21/12/2006 | 16/6/2026 | ESET NOD32 Antivirus before 1.1743 allows remote attackers to cause a denial of service (crash) via a crafted .CHM file that triggers a divide-by-zero error. | |
| Modificada | Alta (9.3) | 5.8% | — | Eset Software Nod32 Antivirus | 21/12/2006 | 16/6/2026 | Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a crafted (1) .DOC or (2) .CAB file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Filseclab Personal Firewall 3.0.0.8686 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Sygate Personal Firewall 5.6.2808 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | AntiHook 3.0.0.23 - Desktop relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (10) | 7.4% | — | Softwin BitdefenderSoftwin Bitdefender AntivirusSoftwin Bitdefender Internet SecuritySoftwin Bitdefender Mail Protection+1 | 18/12/2006 | 16/6/2026 | Integer overflow in the packed PE file parsing implementation in BitDefender products before 20060829, including Antivirus, Antivirus Plus, Internet Security, Mail Protection for Enterprises, and Online Scanner; and BitDefender products for Microsoft ISA Server and Exchange 5.5 through 2003; allows remote attackers to… | |
| Modificada | Alta (7.2) | 0.99% | 💥 Exploit | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Soft4Ever Look 'n' Stop (LnS) 2.05p2 before 20061215 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Media (6.6) | 0.38% | — | Broadcom Etrust AntivirusBroadcom Internet Security Suite | 13/12/2006 | 16/6/2026 | The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs. | |
| Modificada | Media (5) | 2.2% | — | F-prot Antivirus | 10/12/2006 | 16/6/2026 | F-Prot Antivirus for Linux x86 Mail Servers 4.6.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file. | |
| Modificada | Media (5) | 9.4% | 💥 Exploit | Frisk Software F-prot Antivirus | 7/12/2006 | 16/6/2026 | FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinite loop) via a crafted ACE file. NOTE: this issue has at least a partial overlap with CVE-2006-6294. | |
| Modificada | Alta (7.5) | 1.7% | — | Frisk Software F-prot Antivirus | 5/12/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in FRISK Software F-Prot Antivirus before 4.6.7 have unspecified impact and attack vectors. NOTE: this might be related to CVE-2006-6293, but it is not clear due to the vagueness of the report. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | F-prot Antivirus | 5/12/2006 | 16/6/2026 | Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to execute arbitrary code via a crafted CHM file. NOTE: this issue has at least a partial overlap with CVE-2006-6294. | |
| Modificada | Alta (7.8) | 2.7% | — | Grisoft AVG Antivirus | 16/11/2006 | 16/6/2026 | Grisoft AVG Anti-Virus before 7.1.407 allows remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers a divide-by-zero error. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 2.2% | — | Grisoft AVG Antivirus | 16/11/2006 | 16/6/2026 | Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors involving an uninitialized variable and a crafted CAB file. | |
| Modificada | Alta (10) | 2.2% | — | Grisoft AVG Antivirus | 16/11/2006 | 16/6/2026 | Unspecified vulnerability in Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors related to "Integer Issues" and parsing of .EXE files. | |
| Modificada | Alta (7.5) | 4.0% | — | Grisoft AVG Antivirus | 16/11/2006 | 16/6/2026 | Multiple integer overflows in Grisoft AVG Anti-Virus before 7.1.407 allow remote attackers to execute arbitrary code via crafted (1) CAB or (2) RAR archives that trigger a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. |