Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 1.2% | 💥 Exploit | Nullsoft Shoutcast Server | 31/12/2003 | 16/6/2026 | Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL. | |
| Modificada | Alta (10) | 2.5% | — | Castle Rock Computing Snmpc | 20/10/2003 | 16/6/2026 | SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server. | |
| Modificada | Baja (2.1) | 0.48% | — | Nullsoft Shoutcast Server | 22/4/2003 | 16/6/2026 | SHOUTcast 1.8.9 y anteriores permite a usuarios locales obtenter la contraseña administrativa en texto claro mediante una petición GET al puerto 9001, lo que hace que la contraseña sea registrada en el fichero sc_serv.log, con permisos de lectura para todo el mundo. | |
| Modificada | Alta (7.5) | 3.1% | — | Apple Quicktime Darwin MP3 Broadcaster | 7/3/2003 | 16/6/2026 | Desbordamiento de búfer en el módulo de difusión de MP3 en Apple Darwin Streaming Administration Server 4.1.2 y QuickTime Streaming Server 4.1.1 permite a atacantes remotos la ejecución arbitraria de código mediante el uso de un nombre de fichero largo. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Icecast | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Artscore Studios Cutecast Forum | 31/12/2002 | 16/6/2026 | ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Nullsoft Shoutcast Server | 4/10/2002 | 16/6/2026 | Desbordamiento de búfer en SHOUTcast 1.8.9 y otras versiones anteriores a 1.8.12 permite a un DJ autenticado remotamente ejecutar código arbitrario en el servidor mediante un un valor largo en una cabecera cuyo nombre empieza con "icy-" | |
| Modificada | Alta (7.5) | 1.3% | — | Castelle Faxpress | 29/5/2002 | 16/6/2026 | Castelle FaxPress, posiblemente 6.3 y otras versiones, cuando se configura para que se use la cola de impresión Network, permite a los atacantes que obtengan el nombre de usuario y la contraseña si estos envían un login incorrecto, lo que hace que Faxpress envíe el nombre de usuario y contraseña correctos en texto… | |
| Modificada | Alta (7.5) | 3.4% | — | Nullsoft Shoutcast Server | 16/5/2002 | 16/6/2026 | Desbordamiento de buffer en admin.cgi de Nullsoft Shoutcast Server 1.8.3 permite a atacantes remotos causar un denegación de servicio y posiblemente ejecutar código arbitrario con un grán numero de barras invertidas (\\). | |
| Modificada | Alta (7.5) | 9.5% | 💥 Exploit | Icecast | 22/4/2002 | 16/6/2026 | Desbordamientos de buffer en icecast 1.3.11 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante una petición HTTP GET larga de un cliente MP3. | |
| Modificada | Media (5) | 9.4% | 💥 Exploit | Icecast | 18/10/2001 | 16/6/2026 | Vulnerabilidad en el atravesamiento de directorios de Icecast 1.3.10 y anteriores permite a atacantes remotos leer ficheros arbitrarios mediante un ataque modificado .. (punto punto) usando caractéres URL codificados. | |
| Modificada | Alta (7.5) | 1.6% | — | Paul M. Jones Phorecast | 2/10/2001 | 16/6/2026 | Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable. | |
| Modificada | Media (5) | 1.9% | — | Nullsoft Shoutcast Server | 3/8/2001 | 16/6/2026 | Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header. | |
| Modificada | Media (5) | 9.6% | 💥 Exploit | Icecast | 26/6/2001 | 16/6/2026 | Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash). | |
| Modificada | Alta (10) | 3.1% | — | Shoutcast Dnas | 26/3/2001 | 16/6/2026 | Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | IcecastRedhat Linux | 26/3/2001 | 16/6/2026 | Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands. | |
| Modificada | Alta (7.5) | 3.3% | — | Icecast | 13/3/2001 | 16/6/2026 | Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | |
| Modificada | Media (5) | 1.6% | — | Storagesoft Imagecast IC3 | 12/3/2001 | 16/6/2026 | ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002. | |
| Modificada | Alta (7.5) | 3.3% | — | IcecastLibshout | 12/3/2001 | 16/6/2026 | Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | |
| Modificada | Alta (7.2) | 0.34% | — | Nullsoft Shoutcast Server | 20/8/1999 | 16/6/2026 | Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server. |