Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
629 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.41% | — | Broadcom Etrust EZ Antivirus | 10/1/2005 | 16/6/2026 | Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus GatewayBroadcom Etrust EZ Antivirus+18 | 10/1/2005 | 16/6/2026 | El módulo Perl Archive::Zip anterior a 1.14, cuando se usa en programas antivirus como amavisd-new, permite a atacantes remotos saltarse la protección del antivirus mediante un ficheros comprimido con cabeceras globales y locales establecido a cero, lo que no impide que el fichero comprimido sea abierto en un sistema… | |
| Modificada | Media (5) | 1.4% | — | Symantec Norton Antivirus | 31/12/2004 | 16/6/2026 | Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body. | |
| Modificada | Media (5) | 2.7% | — | Broadcom Etrust Antivirus EE | 31/12/2004 | 16/6/2026 | Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files. | |
| Modificada | Media (5) | 1.9% | — | Symantec Norton Antivirus | 3/11/2004 | 16/6/2026 | Symantec Norton Antivirus 2004 y versiones anteriores permiten a un virus u otro código malicioso evitar ser detectados o causar una denegación de servicio (caída de aplicación) usando un nombre de fichero que contenga un nombre de dispositivo de MS-DOS. | |
| Modificada | Alta (10) | 6.4% | — | Symantec Norton Antivirus | 18/8/2004 | 16/6/2026 | Un cierto control ActiveX en Symantec Norton Antivirus 2004 permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar programas de su elección. | |
| Modificada | Media (5) | 6.5% | 💥 Exploit | Symantec Norton Antivirus | 6/8/2004 | 16/6/2026 | Symantec Norton AntiVirus 2002 y 2003 permite a atacantes remotos causar la Denegación de Servicio (por consumo de CPU) mediante un archivo comprimido que contiene un gran número de directorios. | |
| Modificada | Alta (7) | 0.46% | — | Symantec Antivirus Scan Engine | 15/4/2004 | 16/6/2026 | La capacidad LiveUpdate de Symantec Antivirus Scan Engine 4.0 y 4.3 para Red Hat Linux permite a usuarios locales crear o añadir ficheros arbitrarios mediante un ataque de enlaces simbólicos sobre /tmp/LiveUpdate.log. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System WorksSymantec Windows Liveupdate | 3/2/2004 | 16/6/2026 | La funcionalidad gui para una sesión interactiva en ymantec LiveUpdate 1.70.x hasta la 1.90.x (usadas en Norton Internet Security 2001 hasta 2004, SystemWorks 2001 hasta 2004, y AntiVirus y Norton AntiVirus Pro 2001 hasta 2004, AntiVirus for Handhelds v3.0) permite que usuarios locales obtengan privilegios SYSTEM. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | Symantec Norton Antivirus | 31/12/2003 | 16/6/2026 | The DeviceIoControl function in the Norton Device Driver (NAVAP.sys) in Symantec Norton AntiVirus 2002 allows local users to gain privileges by overwriting memory locations via certain control codes (aka "Device Driver Attack"). | |
| Modificada | Media (6.4) | 3.3% | — | Symantec Norton Antivirus | 31/12/2003 | 16/6/2026 | Buffer overflow in Symantec Norton AntiVirus 2002 allows remote attackers to execute arbitrary code via an e-mail attachment with a compressed ZIP file that contains a file with a long filename. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Norton Antivirus | 31/3/2003 | 16/6/2026 | El cliente de Symantec Norton AntiVirus Corporate Edition 7.5.x anteriores a la 7.5.1 Build 62 y 7.6.x anteriores a la 7.6.1 Build 35a ejecutan winhlp32 con privilegios elevados, lo que permite a usuarios locales la obtención de privilegios utilizando ciertas características de winhlp32. | |
| Modificada | Alta (7.2) | 0.69% | — | Eset Software Nod32 Antivirus | 19/2/2003 | 16/6/2026 | Desbordamiento de búfer en Eset Software NOD32 para UNIX anteriores a 1.013 permite a usuarios locales ejecutar código arbitrario mediante un nombre de ruta largo. | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass the initial virus scan and cause NAV to prematurely stop scanning by using a non-RFC compliant MIME header. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed,… | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue,… | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to… | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the… | |
| Modificada | Alta (7.8) | 2.0% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries. | |
| Modificada | Alta (7.5) | 1.5% | — | Symantec Norton Antivirus | 12/8/2002 | 16/6/2026 | Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | |
| Modificada | Media (5) | 3.2% | — | Symantec Norton Antivirus | 7/9/2001 | 16/6/2026 | The default configuration of Norton AntiVirus for Microsoft Exchange 2000 2.x allows remote attackers to identify the recipient's INBOX file path by sending an email with an attachment containing malicious content, which includes the path in the rejection notice. | |
| Modificada | Media (5) | 1.3% | — | Panda Antivirus Platinum | 21/8/2001 | 16/6/2026 | Panda Antivirus Platinum before 6.23.00 allows a remore attacker to cause a denial of service (crash) when a user selects an action for a malformed UPX packed executable file. | |
| Modificada | Alta (10) | 2.0% | — | Novell ClientSymantec Norton Antivirus | 20/10/2000 | 16/6/2026 | Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system. | |
| Modificada | Alta (7.2) | 0.66% | — | Panda Antivirus | 17/6/2000 | 16/6/2026 | The Panda Antivirus console on port 2001 allows local users to execute arbitrary commands without authentication via the CMD command. | |
| Modificada | Media (5) | 2.0% | — | Symantec Norton Antivirus | 14/6/2000 | 16/6/2026 | In some cases, Norton Antivirus for Exchange (NavExchange) enters a "fail-open" state which allows viruses to pass through the server. | |
| Modificada | Media (5) | 2.6% | — | Symantec Norton Antivirus | 14/6/2000 | 16/6/2026 | Buffer overflow in Norton Antivirus for Exchange (NavExchange) allows remote attackers to cause a denial of service via a .zip file that contains long file names. |