Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.38%—Xensource XEN Para Virtualized Frame Buffer23/6/200816/6/2026
The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.
ModificadaMedia (4.3)1.6%—Python Software Foundation Paramiko16/1/200816/6/2026
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
ModificadaMedia (5)1.7%—Ingate FirewallIngate Siparator15/1/200816/6/2026
The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors.
ModificadaAlta (10)1.7%—Ingate FirewallIngate Siparator22/11/200716/6/2026
Buffer overflow in libsrtp in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
ModificadaAlta (10)1.2%—Ingate FirewallIngate Siparator22/11/200716/6/2026
Unspecified vulnerability in the ICMP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 has unknown impact and remote attack vectors, related to ICMP packets that are "incorrectly accepted."
ModificadaAlta (7.1)1.4%—Ingate FirewallIngate Siparator22/11/200716/6/2026
The SRTP implementation in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (kernel crash) via an RTCP index that is "much more than expected."
ModificadaAlta (10)1.9%—Ingate FirewallIngate Siparator22/11/200716/6/2026
Unspecified vulnerability in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 might leave "media pinholes" open upon a restart of the SIP module, which might make it easier for remote attackers to conduct unauthorized activities.
ModificadaAlta (7.5)0.99%—Ingate FirewallIngate Siparator22/11/200716/6/2026
Ingate Firewall before 4.6.0 and SIParator before 4.6.0 do not log truncated (1) ICMP, (2) UDP, and (3) TCP packets, which has unknown impact and remote attack vectors; and do not log (4) serial-console login attempts with nonexistent usernames, which might make it easier for attackers with physical access to guess…
ModificadaMedia (4.3)1.2%—Ingate FirewallIngate Siparator22/11/200716/6/2026
The IPsec module in the VPN component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0 allows remote attackers to cause a denial of service (module crash) via an IPsec Phase 2 proposal that lacks Perfect Forward Secrecy (PFS).
ModificadaMedia (4)0.97%—Ingate FirewallIngate Siparator22/11/200716/6/2026
The SIP component in Ingate Firewall before 4.6.0 and SIParator before 4.6.0, when Remote NAT Traversal is employed, does not properly perform user registration and message distribution, which might allow remote authenticated users to receive messages intended for other users.
ModificadaMedia (5)1.0%—Ingate FirewallIngate Siparator22/11/200716/6/2026
Ingate Firewall before 4.6.0 and SIParator before 4.6.0 use cleartext storage for passwords of "administrators with less privileges," which might allow attackers to read these passwords via unknown vectors.
ModificadaAlta (9.3)6.5%—Callisto Photoparade Player14/9/200716/6/2026
Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property.
ModificadaBaja (1.5)0.27%—HP Address AND Routing Parameter Area(arpa) Transport8/8/200716/6/2026
Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors. NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.
ModificadaAlta (9.3)4.3%—Parallels Confixx26/7/200716/6/2026
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the thisdir parameter.
ModificadaMedia (4)1.0%—Ingate FirewallIngate Siparator11/6/200716/6/2026
Unspecified vulnerability in Ingate Firewall and SIParator before 4.5.2 allows remote authenticated users without full privileges to download a Support Report.
ModificadaMedia (5)1.4%—Ingate FirewallIngate Siparator11/6/200716/6/2026
Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.
ModificadaMedia (6.1)0.60%—Parallels Desktop2/5/200716/6/2026
Parallels allows local users to cause a denial of service (virtual machine abort) via (1) certain INT instructions, as demonstrated by INT 0xAA; (2) an IRET instruction when an invalid address is at the top of the stack; (3) a malformed MOVNTI instruction, as demonstrated by using a register as a destination; or a…
ModificadaMedia (6.8)0.44%—Parallels Desktop2/5/200716/6/2026
Heap-based buffer overflow in the VGA device in Parallels allows local users, with root access to the guest operating system, to terminate the virtual machine and possibly execute arbitrary code in the host operating system via unspecified vectors related to bitblt operations.
ModificadaBaja (3.5)4.5%—Parakey Inc. Firebug11/4/200716/6/2026
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.04 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome by overwriting the toString…
ModificadaMedia (6.8)5.0%—Parakey Inc. Firebug6/4/200716/6/2026
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug extension before 1.03 for Mozilla Firefox allows remote attackers to bypass zone restrictions, read arbitrary file:// URIs, or execute arbitrary code in the browser chrome, as demonstrated via the…
ModificadaAlta (7.2)0.36%—Parallels Desktop2/3/200716/6/2026
Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.
ModificadaMedia (5)1.5%—Hitachi Hirdb Parallel ServerHitachi Hirdb Single ServerHitachi Hirdb Single Server Workgroup EditionHitachi Hirdb Workgroup Server+126/1/200716/6/2026
Hitachi HiRDB Datareplicator 7HiRDB, 7(64), 6, 6(64), 5.0, and 5.0(64); and various products that bundle HiRDB Datareplicator; allows attackers to cause a denial of service (CPU consumption) via certain data.
ModificadaAlta (7.5)1.8%—Ingate Firewall AND Siparator18/1/200716/6/2026
Unspecified vulnerability in the SIP module in InGate Firewall and SIParator before 4.5.1 allows remote attackers to conduct replay attacks on the authentication mechanism via unknown vectors.
ModificadaBaja (2.1)0.29%—Parallels Desktop8/11/200616/6/2026
prl_dhcpd in Parallels Desktop for Mac Build 1940 uses insecure permissions (0666) for /Library/Parallels/.dhcpd_configuration, which allows local users to modify DHCP configuration.
ModificadaMedia (4)2.0%—Ingate FirewallIngate Siparator9/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in the web interface in Ingate Firewall before 4.4.1 and SIParator before 4.4.1 allows remote attackers to inject arbitrary web script or HTML, and steal cookies, via unspecified vectors related to "XSS exploits" in administrator functionality.