Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

570 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)1.2%💥 ExploitNullsoft Shoutcast Server31/12/200316/6/2026
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-url followed by a long URL.
ModificadaAlta (10)2.5%—Castle Rock Computing Snmpc20/10/200316/6/2026
SNMPc 6.0.8 and earlier performs authentication to the server on the client side, which allows remote attackers to gain privileges by decrypting the password that is returned by the server.
ModificadaBaja (2.1)0.48%—Nullsoft Shoutcast Server22/4/200316/6/2026
SHOUTcast 1.8.9 y anteriores permite a usuarios locales obtenter la contraseña administrativa en texto claro mediante una petición GET al puerto 9001, lo que hace que la contraseña sea registrada en el fichero sc_serv.log, con permisos de lectura para todo el mundo.
ModificadaAlta (7.5)3.1%—Apple Quicktime Darwin MP3 Broadcaster7/3/200316/6/2026
Desbordamiento de búfer en el módulo de difusión de MP3 en Apple Darwin Streaming Administration Server 4.1.2 y QuickTime Streaming Server 4.1.1 permite a atacantes remotos la ejecución arbitraria de código mediante el uso de un nombre de fichero largo.
ModificadaMedia (5)3.2%💥 ExploitIcecast31/12/200216/6/2026
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.
ModificadaAlta (7.5)6.7%💥 ExploitArtscore Studios Cutecast Forum31/12/200216/6/2026
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attackers to obtain the passwords via an HTTP request to a .user file.
ModificadaAlta (7.5)5.6%💥 ExploitNullsoft Shoutcast Server4/10/200216/6/2026
Desbordamiento de búfer en SHOUTcast 1.8.9 y otras versiones anteriores a 1.8.12 permite a un DJ autenticado remotamente ejecutar código arbitrario en el servidor mediante un un valor largo en una cabecera cuyo nombre empieza con "icy-"
ModificadaAlta (7.5)1.3%—Castelle Faxpress29/5/200216/6/2026
Castelle FaxPress, posiblemente 6.3 y otras versiones, cuando se configura para que se use la cola de impresión Network, permite a los atacantes que obtengan el nombre de usuario y la contraseña si estos envían un login incorrecto, lo que hace que Faxpress envíe el nombre de usuario y contraseña correctos en texto…
ModificadaAlta (7.5)3.4%—Nullsoft Shoutcast Server16/5/200216/6/2026
Desbordamiento de buffer en admin.cgi de Nullsoft Shoutcast Server 1.8.3 permite a atacantes remotos causar un denegación de servicio y posiblemente ejecutar código arbitrario con un grán numero de barras invertidas (\\).
ModificadaAlta (7.5)9.5%💥 ExploitIcecast22/4/200216/6/2026
Desbordamientos de buffer en icecast 1.3.11 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante una petición HTTP GET larga de un cliente MP3.
ModificadaMedia (5)9.4%💥 ExploitIcecast18/10/200116/6/2026
Vulnerabilidad en el atravesamiento de directorios de Icecast 1.3.10 y anteriores permite a atacantes remotos leer ficheros arbitrarios mediante un ataque modificado .. (punto punto) usando caractéres URL codificados.
ModificadaAlta (7.5)1.6%—Paul M. Jones Phorecast2/10/200116/6/2026
Phorecast PHP script before 0.40 allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.
ModificadaMedia (5)1.9%—Nullsoft Shoutcast Server3/8/200116/6/2026
Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.
ModificadaMedia (5)9.6%💥 ExploitIcecast26/6/200116/6/2026
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).
ModificadaAlta (10)3.1%—Shoutcast Dnas26/3/200116/6/2026
Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.
ModificadaAlta (10)13%💥 ExploitIcecastRedhat Linux26/3/200116/6/2026
Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.5)3.3%—Icecast13/3/200116/6/2026
Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
ModificadaMedia (5)1.6%—Storagesoft Imagecast IC312/3/200116/6/2026
ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002.
ModificadaAlta (7.5)3.3%—IcecastLibshout12/3/200116/6/2026
Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.
ModificadaAlta (7.2)0.34%—Nullsoft Shoutcast Server20/8/199916/6/2026
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.