Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 329 respecto a la semana anterior
Críticas / altas1265▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.0% | — | Nexland Pro800turboSymantec Firewall VPN Appliance 200rSymantec Gateway Security 360Symantec Gateway Security 460 | 2/5/2005 | 16/6/2026 | The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted… | |
| Modificada | Alta (10) | 1.9% | — | Symantec Veritas I3 Focalpoint Server | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact. | |
| Modificada | Baja (2.6) | 1.5% | — | Symantec Antivirus Scan EngineSymantec Mail SecuritySymantec Norton AntivirusSymantec Norton Internet Security+3 | 2/5/2005 | 16/6/2026 | Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on Windows, allows remote attackers to cause a… | |
| Modificada | Media (5) | 1.6% | — | Symantec Enterprise FirewallSymantec VelociraptorSymantec Gateway Security 5300Symantec Gateway Security 5400 | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites. | |
| Modificada | Media (5) | 2.9% | — | Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial of service (system hang or crash) by triggering a scan of a certain file type. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | HP Java Sdk-rteSUN JDKSUN JRESymantec Enterprise Firewall+4 | 1/3/2005 | 16/6/2026 | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API… | |
| Modificada | Alta (7.5) | 19% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+7 | 8/2/2005 | 16/6/2026 | Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header. | |
| Modificada | Alta (10) | 82% | 💥 Exploit | Symantec Veritas Backup Exec | 10/1/2005 | 16/6/2026 | Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9.1.4691 Hotfix 40, allows remote attackers to execute arbitrary code via a registration request with a long hostname. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Symantec Security Check Virus Detection | 31/12/2004 | 16/6/2026 | rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged. | |
| Modificada | Media (5) | 3.9% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a… | |
| Modificada | Media (5) | 1.4% | — | Symantec Norton Antivirus | 31/12/2004 | 16/6/2026 | Unknown versions of Symantec Norton AntiVirus and Microsoft Outlook allow attackers to cause a denial of service (crash) via malformed e-mail messages (1) without a body or (2) without a carriage return ("\n") separating the headers from the body. | |
| Modificada | Alta (7.2) | 0.45% | — | Symantec Altiris Client ServiceAI | 31/12/2004 | 16/6/2026 | The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590. | |
| Modificada | Media (5) | 3.2% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file. | |
| Modificada | Baja (2.1) | 0.38% | — | Symantec Powerquest Deploycenter | 31/12/2004 | 16/6/2026 | The stuffit.com executable on Symantec PowerQuest DeployCenter 5.5 boot disks allows local users to obtain sensitive information (an unencrypted password for a Windows domain account) via four "stuffit /f:stuffit.dat" invocations, possibly due to a buffer overflow. | |
| Modificada | Alta (7.2) | 0.35% | — | Symantec Veritas Cluster Server | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Veritas Cluster Server 1.0.1 through 4.0 allows local users to gain root access via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Symantec WEB Security | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Symantec Web Security 2.5, 3.0.0, and 3.0.1 before build 62 allows remote attackers to inject arbitrary web script or HTML via the query string in blocked URLs that are listed in (1) error or (2) block page messages. | |
| Modificada | Alta (10) | 2.4% | — | Symantec Clientless VPN Gateway 4400 | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in the ActiveX and HTML file browsers in Symantec Clientless VPN Gateway 4400 Series 5.0 have unknown attack vectors and unknown impact. | |
| Modificada | Media (5) | 3.7% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security+6 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface. | |
| Modificada | Alta (7.5) | 4.4% | — | Entrust Libkmp Isakmp LibrarySymantec Enterprise FirewallSymantec VelociraptorSymantec Gateway Security 5300+1 | 31/12/2004 | 16/6/2026 | Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload. | |
| Modificada | Media (5) | 2.1% | — | Symantec Brightmail Antispam | 17/12/2004 | 16/6/2026 | The character converters in the Spamhunter and Language ID modules for Symantec Brightmail AntiSpam 6.0.1 before patch 132 allow remote attackers to cause a denial of service (crash) via messages with the ISO-8859-10 character set, which is not recognized by the converters. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 1.9% | — | Symantec Norton Antivirus | 3/11/2004 | 16/6/2026 | Symantec Norton Antivirus 2004 y versiones anteriores permiten a un virus u otro código malicioso evitar ser detectados o causar una denegación de servicio (caída de aplicación) usando un nombre de fichero que contenga un nombre de dispositivo de MS-DOS. | |
| Modificada | Alta (7.5) | 1.8% | — | Symantec ON Command CCMSymantec ON Icommand | 21/9/2004 | 16/6/2026 | Symantec ON Command CCM 5.4.x and iCommand 3.0.x has four default usernames and passwords, one of which is hardcoded, which allows remote attackers to gain unauthorized access. |