Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

552 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)8.9%💥 ExploitApache Http Server18/10/200116/6/2026
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.
ModificadaMedia (5)57%💥 ExploitApache Http Server1/10/200116/6/2026
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string.
ModificadaMedia (5)4.3%—Apache Http Server31/8/200116/6/2026
Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail.
ModificadaAlta (7.2)0.58%—IBM Http Server SSL Module Common31/8/200116/6/2026
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http ServerVwebserver29/6/200116/6/2026
SmallHTTP 1.204 through 3.00 beta 8 allows remote attackers to cause a denial of service via multiple long URL requests.
ModificadaMedia (5)1.6%—MAX Feoktistov Small Http Server27/6/200116/6/2026
Small HTTP server 2.03 allows remote attackers to cause a denial of service via a URL that contains an MS-DOS device name such as aux.
ModificadaMedia (5)12%—Apache Http Server12/5/200116/6/2026
Apache before 1.3.20 on Windows and OS/2 systems allows remote attackers to cause a denial of service (GPF) via an HTTP request for a URI that contains a large number of / (slash) or other characters, which causes certain functions to dereference a null pointer.
ModificadaAlta (10)3.3%—A1webserver Http Server3/5/200116/6/2026
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.
ModificadaAlta (7.5)7.9%💥 ExploitBajie Java Http Server3/5/200116/6/2026
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
ModificadaAlta (7.5)3.7%💥 ExploitBajie Java Http Server3/5/200116/6/2026
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.
ModificadaMedia (5)3.0%💥 ExploitA1webserver Http Server3/5/200116/6/2026
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.
ModificadaMedia (5)3.3%💥 ExploitIBM Http ServerIBM Websphere Application Server13/3/200116/6/2026
Kernel leak in AfpaCache module of the Fast Response Cache Accelerator (FRCA) component of IBM HTTP Server 1.3.x and Websphere 3.52 allows remote attackers to cause a denial of service via a series of malformed HTTP requests that generate a "bad request" error.
ModificadaMedia (5)75%💥 ExploitApache Http ServerDebian Linux12/3/200116/6/2026
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.
ModificadaBaja (3.3)2.3%—Apache Http ServerDebian Linux12/3/200116/6/2026
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.
ModificadaMedia (5)9.6%💥 ExploitApache Http Server16/2/200116/6/2026
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack containing "%5c" (encoded backslash) sequences.
ModificadaMedia (5)1.3%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.
ModificadaMedia (5)3.3%💥 ExploitMAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL that references a directory that does not contain an index.html file, which consumes memory that is not released after the request is completed.
ModificadaAlta (7.5)1.9%—IBM Http Server9/1/200116/6/2026
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.
ModificadaMedia (5)1.2%—MAX Feoktistov Small Http Server9/1/200116/6/2026
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.
ModificadaMedia (5)36%—Apache Http Server19/12/200023/9/2026
mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.
ModificadaMedia (5)1.3%—Fastream FUR Http Server14/11/200016/6/2026
Fastream FUR HTTP server 1.0b allows remote attackers to cause a denial of service via a long GET request.
ModificadaMedia (5)51%💥 ExploitApache Http ServerSuse Linux14/11/200016/6/2026
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbitrary directories via the PROPFIND HTTP request method.
ModificadaMedia (5)45%—Apache Http ServerSuse Linux14/11/200016/6/2026
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.
ModificadaMedia (5)1.9%—Bajie Java Http Server20/10/200016/6/2026
Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack.
ModificadaMedia (5)1.5%—Bajie Java Http Server20/10/200016/6/2026
The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.
Orbitaley — Vulnerabilidades