Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 350 respecto a la semana anterior
Críticas / altas1260▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Symantec Norton System Works | 11/1/2006 | 16/6/2026 | Symantec Norton SystemWorks and SystemWorks Premier 2005 and 2006 stores temporary copies of files in the Norton Protected Recycle Bin NProtect directory, which is hidden from the FindFirst and FindNext Windows APIs and allows remote attackers to hide arbitrary files from virus scanners and other products. | |
| Modificada | Media (5) | 2.7% | — | Symantec Brightmail Antispam | 31/12/2005 | 16/6/2026 | Symantec Brightmail AntiSpam 6.0 build 1 and 2 allows remote attackers to cause a denial of service (bmserver component termination) via malformed MIME messages. | |
| Modificada | Alta (7.8) | 9.5% | 💥 Exploit | Symantec Pcanywhere | 1/12/2005 | 16/6/2026 | Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors. | |
| Modificada | Alta (7.5) | 3.8% | — | Symantec Enterprise FirewallSymantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Gateway Security 300+6 | 23/11/2005 | 16/6/2026 | Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as… | |
| Modificada | Alta (10) | 28% | 💥 Exploit | Symantec Veritas Netbackup | 18/11/2005 | 16/6/2026 | Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Symantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System | 16/11/2005 | 16/6/2026 | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,… | |
| Modificada | Alta (7.5) | 1.4% | — | Symantec DiscoverySymantec ON Command Discovery | 27/10/2005 | 16/6/2026 | The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting another password. | |
| Modificada | Alta (7.2) | 0.36% | — | Symantec Norton Antivirus | 21/10/2005 | 16/6/2026 | Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file. | |
| Modificada | Alta (7.2) | 0.42% | — | Symantec Norton Antivirus | 20/10/2005 | 16/6/2026 | ** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a CNA error, this candidate was also originally assigned to an issue in DiskMountNotify. Use CVE-2005-3270 for the… | |
| Modificada | Media (5.1) | 1.7% | — | Symantec Antivirus Scan Engine | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Symantec Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Alta (10) | 60% | 💥 Exploit | Symantec Veritas Netbackup Data AND Business CenterSymantec Veritas Netbackup Enterprise Server Client | 12/10/2005 | 16/6/2026 | Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command. | |
| Modificada | Alta (10) | 13% | — | Symantec Antivirus Scan EngineSymantec Antivirus Scan Engine FOR Network Attached Storage | 5/10/2005 | 16/6/2026 | Integer signedness error in the administrative interface for Symantec AntiVirus Scan Engine 4.0 and 4.3 allows remote attackers to execute arbitrary code via crafted HTTP headers with negative values, which lead to a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 5.6% | — | Symantec Veritas Storage ExecSymantec Veritas Storagecentral | 20/9/2005 | 16/6/2026 | Multiple heap-based and stack-based buffer overflows in certain DCOM server components in VERITAS Storage Exec Storage Exec 5.3 before Hotfix 9 and StorageCentral 5.2 before Hot Fix 2 allow remote attackers to execute arbitrary code via certain ActiveX controls. | |
| Modificada | Baja (2.1) | 0.40% | — | Symantec Norton Antivirus | 2/9/2005 | 16/6/2026 | Symantec AntiVirus Corporate Edition 9.0.1.x and 9.0.4.x, and possibly other versions, when obtaining updates from an internal LiveUpdate server, stores sensitive information in cleartext in the Log.Liveupdate log file, which allows attackers to obtain the username and password to the internal LiveUpdate server. | |
| Modificada | Alta (10) | 1.7% | — | Symantec Norton Antivirus | 30/8/2005 | 16/6/2026 | Symantec AntiVirus 9 Corporate Edition allows local users to gain privileges via the "Scan for viruses" option, which launches a help window with raised privileges, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2002-1540. | |
| Modificada | Alta (10) | 87% | 💥 Exploit | Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote AgentSymantec Veritas Netbackup | 17/8/2005 | 16/6/2026 | VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the… | |
| Modificada | Alta (7.5) | 5.2% | — | Symantec Veritas Backup Exec | 2/8/2005 | 16/6/2026 | Desbordamiento de búfer en Admin Plus Pack Option for VERITAS Backup Exec 9.0 hasta 10.0 para Windows Servers permite que atacantes remotos ejecuten código arbitrario. | |
| Modificada | Media (5) | 1.1% | — | Symantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 27/7/2005 | 16/6/2026 | NDMP server en Veritas NetBackup 5.1 permite que atacantes causen una denegación de servicio mediante un mensaje CONFIG con fecha fuera de rango, lo que provoca intento de acceso a puntero nulo. | |
| Modificada | Alta (7.5) | 1.5% | — | Symantec Veritas Backup Exec | 29/6/2005 | 16/6/2026 | Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server. | |
| Modificada | Alta (7.5) | 3.2% | — | Symantec Veritas Backup Exec | 28/6/2005 | 16/6/2026 | Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (10) | 54% | — | Symantec Veritas Backup Exec | 23/6/2005 | 16/6/2026 | VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106. | |
| Modificada | Alta (7.5) | 86% | 💥 Exploit | Symantec Veritas Backup Exec | 18/6/2005 | 16/6/2026 | Stack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware allows remote attackers to execute arbitrary code via a CONNECT_CLIENT_AUTH request with authentication method type 3 (Windows credentials) and a long password argument. | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Pcanywhere | 16/6/2005 | 16/6/2026 | Symantec pcAnywhere 10.5x and 11.x before 11.5, with "Launch with Windows" enabled, allows local users with physical access to execute arbitrary commands via the Caller Properties feature. | |
| Modificada | Alta (7.5) | 1.6% | — | Symantec Brightmail Antispam | 9/6/2005 | 16/6/2026 | Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges. | |
| Modificada | Baja (2.1) | 0.45% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 2/5/2005 | 16/6/2026 | The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (CPU consumption and system crash) by renaming a file on a network share. |