Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
610 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | — | Ipswitch Imail | 6/7/2005 | 16/6/2026 | IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Ipswitch Whatsup | 22/6/2005 | 16/6/2026 | SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the (1) User Name field (sUserName parameter) or (2) Password (sPassword parameter). | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (10) | 59% | — | Ipswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite | 25/5/2005 | 16/6/2026 | Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name. | |
| Modificada | Media (5) | 4.5% | — | Ipswitch Collaboration Suite | 25/5/2005 | 16/6/2026 | The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop. | |
| Modificada | Media (5) | 5.1% | — | Ipswitch Imail | 25/5/2005 | 16/6/2026 | Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument. | |
| Modificada | Media (5) | 12% | — | Ipswitch ImailIpswitch Imail Server | 25/5/2005 | 16/6/2026 | Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file. | |
| Modificada | Alta (10) | 43% | 💥 Exploit | Ipswitch ImailIpswitch Imail ServerIpswitch Collaboration Suite | 25/5/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins… | |
| Modificada | Media (5) | 8.4% | 💥 Exploit | Ipswitch Imail | 2/5/2005 | 16/6/2026 | Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password. | |
| Modificada | Alta (7.2) | 2.0% | — | Ipswitch Collaboration Suite | 2/5/2005 | 16/6/2026 | Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command. | |
| Modificada | Media (5) | 50% | 💥 Exploit | Ipswitch WS FTP Server | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands. | |
| Modificada | Media (5) | 8.1% | — | Ipswitch WS FTP ServerProgress WS FTP Server | 31/12/2004 | 16/6/2026 | Ipswitch WS_FTP Server 4.0.2 allows remote attackers to cause a denial of service (disk consumption) and bypass file size restrictions via a REST command with a large size argument, followed by a STOR of a smaller file. | |
| Modificada | Alta (7.5) | 3.5% | — | Ipswitch Imail Express | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." | |
| Modificada | Alta (7.1) | 39% | — | 3com 3c17205-us3com 3c17210-us3com Superstack 3 Switch | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in 3Com SuperStack 3 4400 switches with firmware version before 3.31 allows remote attackers to cause a denial of service (device reset) via a crafted request to the web management interface. NOTE: the provenance of this information is unknown; details are obtained from third party reports. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Yatsoft Switch OFF | 31/12/2004 | 16/6/2026 | swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a long packet with two CRLF sequences to the service management port (TCP 8000). | |
| Modificada | Alta (7.5) | 5.8% | 💥 Exploit | Yatsoft Switch OFF | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execute arbitrary code via a long message parameter in a SendMsg action to action.htm. | |
| Modificada | Media (5) | 4.9% | — | Ipswitch Imail | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "specific content." | |
| Modificada | Baja (2.1) | 0.89% | 💥 Exploit | Im-switch | 31/12/2004 | 16/6/2026 | im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file. | |
| Modificada | Media (5) | 1.8% | — | Alcatel OmniswitchAlcatel Omniswitch 7800 | 31/12/2004 | 16/6/2026 | Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled. | |
| Modificada | Media (4.6) | 89% | 💥 Exploit | Ipswitch Imail | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. | |
| Modificada | Media (5) | 7.1% | — | Ipswitch Imail | 31/12/2004 | 16/6/2026 | Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Manager or (2) a long To field to the Web Messaging component. | |
| Modificada | Alta (7.5) | 1.5% | — | Asante Fm2008 Managed Ethernet Switch | 15/12/2004 | 16/6/2026 | Asante FM2008 running firmware 1.06 is shipped with a default username and password, which could allow remote attackers to gain unauthorized access. | |
| Modificada | Alta (7.5) | 1.3% | — | Asante Fm2008 Managed Ethernet Switch | 15/12/2004 | 16/6/2026 | The configuration backup in Asante FM2008 running firmware 1.06 stores the username and password in cleartext, which could allow remote attackers to gain unauthorized access. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read. | |
| Modificada | Media (5) | 3.2% | — | Cisco Content Services Switch 11000Cisco Content Services Switch 11050Cisco Content Services Switch 11150Cisco Content Services Switch 11800 | 23/11/2004 | 16/6/2026 | Cisco 11000 Series Content Services Switches (CSS) running WebNS 5.0(x) before 05.0(04.07)S, and 6.10(x) before 06.10(02.05)S allow remote attackers to cause a denial of service (device reset) via a malformed packet to UDP port 5002. |