Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2699▼ 343 respecto a la semana anterior
Críticas / altas1270▼ 197 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)208▼ 123 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.5% | — | Symantec Gateway Security | 6/9/2006 | 16/6/2026 | ** DISCUTIDO ** El servicio proxy DNS en Symantec Gateway Security (SGS) permite a un atacante remoto hacer consultas DNS de su elección a los servidores DNS de terceras personas, mientras se ocultan la dirección IP de origen del atacante. NOTA: otro investigador ha señalado que la configuración por defecto no recibe… | |
| Modificada | Media (5) | 2.9% | — | Symantec Enterprise Security Manager | 23/8/2006 | 16/6/2026 | El servidor de administración en Symantec Enterprise Security Manager (ESM) 6 y 6.5.x permite a atacantes remotos provocar una denegación de servicio (la aplicación no responde) mediante una petición de agente ESM mal formada. | |
| Modificada | Baja (3.6) | 0.35% | — | Symantec Norton Personal Firewall | 21/8/2006 | 16/6/2026 | Symantec Norton Personal Firewall 2006 9.1.0.33, y posiblemente anteriores, no protege adecuadamente las claves de registro de Norton, lo cual permite a usuarios locales proporcionar librerías a modo de troyanos a Norton mediante el uso de RegSaveKey y RegRestoreKey para modificar… | |
| Modificada | Alta (9) | 2.9% | — | Symantec Veritas Netbackup Puredisk Remote Office Edition | 18/8/2006 | 16/6/2026 | Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 anterior a MP1 16/08/2006 permite a atacantes remotos evitar la autenticación y obtener privilegios mediante vectores de ataque desconocidos en la interfaz de administración. | |
| Modificada | Media (6.5) | 5.8% | — | Symantec Veritas Backup Exec | 14/8/2006 | 16/6/2026 | Múliples desbordamientos de búfer en Symantec VERITAS Backup Exec para Netware Server Remote Agent para Windows Server 9.1 y 9.2 (todas las construcciones), Backup Exec Continuous Protection Server Remote Agent para Windows Server 10.1 (10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, y 10.1.327.401), y… | |
| Modificada | Alta (7.6) | 4.5% | — | Symantec Brightmail Antispam | 7/8/2006 | 16/6/2026 | Múltiples vulnerabilidades de salto de directorio en Symantec Brightmail AntiSpam (SBAS) anterior a 6.0.4, cuando está permitido conectarse al Centro de Control desde cualquier ordenador, permite a atacantes remotos leer y sobrescribir ciertos ficheros mediante secuencias de salto de directorio en peticiones… | |
| Modificada | Media (5) | 1.7% | — | Symantec Brightmail Antispam | 7/8/2006 | 16/6/2026 | Symantec Brightmail AntiSpam (SBAS) anterior a 6.0.4, cuando está permitido conectarse al Centro de Control desde cualquier ordenador, permite a atacantes remotos provocar una denegación de servicio (congelación de la aplicación) enviando peticiones inválidas. | |
| Modificada | Baja (2.1) | 0.23% | — | Symantec On-demand AgentSymantec On-demand Protection | 5/8/2006 | 16/6/2026 | Symantec On-Demand Agent (SODA) anterior a 2.5 MR2 Build 2157, y el módulo Virtual Desktop en Symantec On-Demand Protection (SODP) anterior 2.6 Build 2233, no encripta de forma adecuada archivos que estén sujetos a la política de encriptación automática, lo cual permitiría a un usuario local leer datos sensible a… | |
| Modificada | Baja (3.6) | 0.40% | — | Symantec Pcanywhere | 24/7/2006 | 16/6/2026 | Symantec pcAnywhere 12.5 utiliza protección de integridad débil para los ficheros .cif (también conocido como caller o CallerID), lo cual permite a usuarios locales generar un fichero .cif personalizado y modificar la bandera de super-usuario. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Pcanywhere | 24/7/2006 | 16/6/2026 | Symantec pcAnywhere 12.5 utiliza unos permisos por defecto débiles para la carpeta "Symantec\pcAnywhere\Hosts", lo cual permite a un usuario local ganar privilegios a través de la insercción de un superusuario archivo .cif (también conocido como llamador o CallerID) dentro de la carpeta, y por lo tanto utilizando un… | |
| Modificada | Baja (2.1) | 0.40% | — | Symantec Pcanywhere | 24/7/2006 | 16/6/2026 | Symantec pcAnywhere 12.5 ofusca la contraseña en un cuadro de texto del GUI con asteriscos, pero no la encripta en el fichero .cif asociado (también conocido como caller o CallerID), lo que permite a usuarios locales obtener la contraseña de la ventana utilizando herramientas como el Nirsoft Asterwin. | |
| Modificada | Baja (2.1) | 0.40% | — | Symantec Norton Personal Firewall | 21/7/2006 | 16/6/2026 | Norton Personal Firewall 2006 9.1.0.33 permite a usuarios locales provocar denegación de servicio (caida) a través de ciertas operaciones de RegSaveKey, RegRestoreKey y RegDeleteKey sobre las llaves del registro (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc y (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent | |
| Modificada | Media (4.6) | 0.47% | — | Symantec Security Information Manager | 19/6/2006 | 16/6/2026 | Librería M4 Macro de Symantec Security Information Manager anteriores a 4.0.2.29 HOTFIX 1 permiste a usuarios locales ejecutar comandos arbitrarios a través de "reglas de definición" modificadas, lo que produce código Java peligroso durante la transformación M4. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Symantec Client SecuritySymantec Norton Antivirus | 27/5/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en Symantec Antivirus 10.1 y Client Security 3.1 permite a atacantes remotos ejecutar código de su elección vectores de ataque desconocidos. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Symantec Enterprise FirewallSymantec Gateway Security | 12/5/2006 | 16/6/2026 | The HTTP proxy in Symantec Gateway Security 5000 Series 2.0.1 and 3.0, and Enterprise Firewall 8.0, when NAT is being used, allows remote attackers to determine internal IP addresses by using malformed HTTP requests, as demonstrated using a get request without a space separating the URI. | |
| Modificada | Media (6.4) | 1.9% | — | Symantec Antivirus Scan Engine | 25/4/2006 | 16/6/2026 | Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses the same private DSA key for each installation, which allows remote attackers to conduct man-in-the-middle attacks and decrypt communications. | |
| Modificada | Media (5) | 2.4% | — | Symantec Antivirus Scan Engine | 25/4/2006 | 16/6/2026 | Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, stores sensitive log and virus definition files under the web root with insufficient access control, which allows remote attackers to obtain the information via direct requests. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Symantec Antivirus Scan Engine | 25/4/2006 | 16/6/2026 | Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests. | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Baja (3.2) | 0.32% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, gives read and write permissions to all users for database shared memory sections, which allows local users to access and possibly modify certain information. | |
| Modificada | Baja (2.1) | 0.39% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | Buffer overflow in the login dialog in dbisqlc.exe in SQLAnywhere for Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, might allow local users to read certain sensitive information from the database. | |
| Modificada | Media (4.6) | 0.36% | — | Symantec Ghost Solutions SuiteSymantec Norton Ghost | 19/3/2006 | 16/6/2026 | The installation of SQLAnywhere in Symantec Ghost 8.0 and 8.2, as used in Symantec Ghost Solutions Suite (SGSS) 1.0, includes a default administrator login account and password, which allows local users to gain privileges or modify tasks. | |
| Modificada | Media (5) | 2.2% | — | Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote Agent | 19/3/2006 | 16/6/2026 | Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors." | |
| Modificada | Media (4.6) | 1.9% | — | Symantec Veritas Backup Exec | 19/3/2006 | 16/6/2026 | Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Symantec Sygate Management Server | 2/2/2006 | 16/6/2026 | SQL injection vulnerability in the Authentication Servlet in Symantec Sygate Management Server (SMS) version 4.1 build 1417 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via unknown attack vectors related to a URL. |