Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | 3com Superstack 3 Switch 4400 | 25/10/2006 | 16/6/2026 | 3Com Switch SS3 4400 switches, firmware 5.11, 6.00 and 6.10 and earlier, allow remote attackers to read the SNMP Read-Write Community string and conduct unauthorized actions via unspecified "normally restricted management packets on the device" that cause the community string to be returned. | |
| Modificada | Media (6.5) | 65% | — | Ipswitch WS FTP ServerProgress WS FTP Server | 26/9/2006 | 16/6/2026 | Multiple buffer overflows in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, have unknown impact and remote authenticated attack vectors via the (1) XCRC, (2) XMD5, and (3) XSHA1 commands. NOTE: in the early publication of this identifier on 20060926, the description was used for the wrong… | |
| Modificada | Media (5) | 32% | — | Ipswitch WS FTP ServerProgress WS FTP Server | 26/9/2006 | 16/6/2026 | Unspecified vulnerability in the log analyzer in WS_FTP Server 5.05 before Hotfix 1, and possibly other versions down to 5.0, prevents certain sensitive information from being displayed in the (1) Files and (2) Summary tabs. NOTE: in the early publication of this identifier on 20060926, the description was used for… | |
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Ipswitch WS FTP Server | 25/9/2006 | 16/6/2026 | Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command. | |
| Modificada | Media (6.5) | 85% | 💥 Exploit | Ipswitch WS FTP ServerProgress WS FTP Server | 19/9/2006 | 16/6/2026 | Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands. | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Ipswitch Imail PlusIpswitch Imail Secure ServerIpswitch Collaboration Suite | 8/9/2006 | 16/6/2026 | Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character. | |
| Modificada | Media (5) | 1.3% | — | Cisco Content Services Switch 11000 | 25/8/2006 | 16/6/2026 | The ArrowPoint cookie functionality for Cisco 11000 series Content Service Switches specifies an internal IP address if the administrator does not specify a string option, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 4.4% | — | HP Procurve Switch 3500ylHP Procurve Switch 5400zlHP Procurve Switch 6200yl | 7/8/2006 | 16/6/2026 | Hewlett-Packard (HP) ProCurve 3500yl, 6200yl, and 5400zl switches with software before K.11.33 allow remote attackers to cause a denial of service (possibly memory leak or system crash) via unknown vectors. | |
| Modificada | Media (6.4) | 2.5% | — | Ipswitch Collaboration SuiteIpswitch Secure Server | 13/7/2006 | 16/6/2026 | Premium Anti-Spam in Ipswitch IMail Secure Server 2006 and Collaboration Suite 2006 Premium, when using a certain .dat file in the StarEngine /data directory from 20060630 or earlier, does not properly receive and implement bullet signature updates, which allows context-dependent attackers to use the server for spam… | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Ipswitch Whatsup | 22/5/2006 | 16/6/2026 | Ipswitch WhatsUp Professional 2006 only verifies the user's identity via HTTP headers, which allows remote attackers to spoof being a trusted console and bypass authentication by setting HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole". | |
| Modificada | Media (5) | 3.8% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium allows remote attackers to obtain full path information via 404 error messages. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 2.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is… | |
| Modificada | Media (5) | 3.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain source code for scripts via a trailing dot in a request to NmConsole/Login.asp. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b)… | |
| Modificada | Media (5) | 5.5% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/utility/RenderMap.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to obtain sensitive information about network nodes via a modified nDeviceGroupID parameter. | |
| Modificada | Media (5) | 3.8% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (5) | 3.1% | — | Ipswitch Whatsup Professional | 15/5/2006 | 16/6/2026 | NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users to other websites via the (1) sCancelURL and possibly (2) sRedirectUrl parameters. | |
| Modificada | Media (5) | 1.9% | — | Cisco Content Services Switch 11500 | 5/4/2006 | 16/6/2026 | Unspecified vulnerability in the HTTP compression functionality in Cisco CSS 11500 Series Content Services switches allows remote attackers to cause a denial of service (device reload) via (1) "valid, but obsolete" or (2) "specially crafted" HTTP requests. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Ipswitch Whatsup | 28/2/2006 | 16/6/2026 | NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "["… | |
| Modificada | Media (5) | 64% | 💥 Exploit | Ipswitch Whatsup Small Business | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in Ipswitch WhatsUp Small Business 2004 allows remote attackers to read arbitrary files via ".." (dot dot) sequences in a request to the Report service (TCP 8022). | |
| Modificada | Media (6.5) | 7.4% | — | Ipswitch Collaboration Suite | 31/12/2005 | 16/6/2026 | Buffer overflow in the IMAP daemon in Ipswitch Collaboration Suite 2006.02 and earlier allows remote authenticated users to execute arbitrary code via a long FETCH command. | |
| Modificada | Media (4) | 11% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which causes IMail Server to reference invalid memory. | |
| Modificada | Alta (7.5) | 4.7% | — | Ipswitch Imail ServerIpswitch Collaboration Suite | 7/12/2005 | 16/6/2026 | Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers to the (1) EXPN, (2) MAIL, (3) MAIL FROM, and (4) RCPT TO commands. | |
| Modificada | Media (5) | 1.0% | — | Cisco Content Services Switch 11500 | 2/11/2005 | 16/6/2026 | Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation. | |
| Modificada | Baja (2.1) | 0.35% | — | Mcdata Intrepid 6064 Director SwitchMcdata Intrepid 6140 Director SwitchMcdata Sphereon 4300 Fabric SwitchMcdata Sphereon 4500 Fabric Switch | 7/8/2005 | 16/6/2026 | Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm. |