Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

610 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)68%💥 ExploitIpswitch Imail23/11/200416/6/2026
Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.
ModificadaAlta (7.5)9.5%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
ModificadaMedia (5)7.2%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
ModificadaMedia (5)6.2%—Ipswitch Whatsup GoldProgress Whatsup Gold20/10/200416/6/2026
The HTTP daemon in Ipswitch WhatsUp Gold 8.03 and 8.03 Hotfix 1 allows remote attackers to cause a denial of service (server crash) via a GET request containing an MS-DOS device name, as demonstrated using "prn.htm".
ModificadaMedia (5)4.2%—Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+24/9/200416/6/2026
Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets.
ModificadaAlta (7.5)1.5%—Securecomputing Smartether Ss6215s Switch26/4/200416/6/2026
Samsung SmartEther SS6215S switch, and possibly other Samsung switches, allows remote attackers and local users to gain administrative access by providing the admin username followed by a password that is the maximum allowed length, then pressing the enter key after the resulting error message.
ModificadaAlta (7.5)5.8%—Ipswitch WS FTP PROIpswitch WS FTP ServerProgress WS FTP Server23/3/200416/6/2026
Ipswitch WS_FTP Server 4.0.2 has a backdoor XXSESS_MGRYY username with a default password, which allows remote attackers to gain access.
ModificadaMedia (5)2.1%—Cisco Content Services Switch 11000Cisco Content Services Switch 1150031/12/200316/6/2026
The DNS server for Cisco Content Service Switch (CSS) 11000 and 11500, when prompted for a nonexistent AAAA record, responds with response code 3 (NXDOMAIN or "Name Error") instead of response code 0 ("No Error"), which allows remote attackers to cause a denial of service (inaccessible domain) by forcing other DNS…
ModificadaMedia (5)6.1%—Cisco IOSCisco Css11000 Content Services SwitchCisco PIX FirewallOpenssl+11/12/200316/6/2026
OpenSSL 0.9.6k allows remote attackers to cause a denial of service (crash via large recursion) via malformed ASN.1 sequences.
ModificadaAlta (10)66%—Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+146/10/200316/6/2026
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
ModificadaAlta (7.5)22%💥 ExploitSendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+106/10/200316/6/2026
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
ModificadaAlta (7.5)85%💥 ExploitIpswitch WS FTP ServerProgress WS FTP Server22/9/200316/6/2026
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
ModificadaAlta (7.8)20%💥 ExploitHP Procurve Switch 4000m11/4/200316/6/2026
HP ProCurve Switch 4000M C.07.23 allows remote attackers to cause a denial of service (crash) via an SNMP write request containing 85 characters, possibly triggering a buffer overflow.
ModificadaMedia (5)7.0%💥 ExploitEnterasys Smartswitch Ssr80002/4/200316/6/2026
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cause a denial of service (crash) via multiple port scans to ports 15077 and 15078.
ModificadaAlta (10)39%💥 ExploitSendmailSendmail SwitchCompaq Tru64Hp-ux+52/4/200316/6/2026
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial…
ModificadaMedia (4.6)0.33%—Sebastian Dehne PP Powerswitch31/12/200216/6/2026
Unknown vulnerability in Parallel port powerSwitch (aka pp_powerSwitch) 0.1 does not properly enforce access controls, which allows local users to access arbitrary ports.
ModificadaAlta (7.5)3.4%—Ipswitch WS FTP PRO31/12/200216/6/2026
Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors.
ModificadaAlta (7.1)6.7%💥 ExploitHP Procurve Switch 4000m11/10/200216/6/2026
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remote administration enabled, does not authenticate requests to reset the device, which allows remote attackers to cause a denial of service via a direct request to the device_reset CGI program.
ModificadaAlta (7.5)14%💥 ExploitIpswitch Imail4/10/200216/6/2026
Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.
ModificadaAlta (7.1)3.3%—Cisco IOSCisco PIX Firewall SoftwareCisco Css11000 Content Services SwitchCisco Catos4/10/200216/6/2026
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).
ModificadaMedia (5)11%💥 ExploitIpswitch Imail4/10/200216/6/2026
IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.
ModificadaAlta (7.5)1.5%—Cisco WebnsCisco Content Services Switch 110005/9/200216/6/2026
The original patch for the Cisco Content Service Switch 11000 Series authentication bypass vulnerability (CVE-2001-0622) was incomplete, which still allows remote attackers to gain additional privileges by directly requesting the web management URL instead of navigating through the interface, possibly via a variant of…
ModificadaAlta (10)10%—Ipswitch Imail12/8/200216/6/2026
Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter.
ModificadaMedia (5)2.5%—Cisco WebnsCisco Content Services Switch 1100012/8/200216/6/2026
The web management interface for Cisco Content Service Switch (CSS) 11000 switches allows remote attackers to cause a denial of service (soft reset) via (1) an HTTPS POST request, or (2) malformed XML data.
ModificadaAlta (7.5)20%💥 ExploitNortel CVX 1800 Multi-service Access Switch3/7/200216/6/2026
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.