Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 6.8% | — | Computer Associates Arcserve Backup Laptops AND DesktopsComputer Associates Desktop AND Server ManagementComputer Associates Desktop Management SuiteComputer Associates Unicenter Asset Management+3 | 16/4/2008 | 16/6/2026 | The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote… | |
| Modificada | Alta (10) | 70% | 💥 Exploit | Asus Remote Console | 25/3/2008 | 16/6/2026 | Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623. | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Computer Associates Brightstor Arcserve Backup Laptops DesktopsComputer Associates Desktop Management SuiteComputer Associates Unicenter DSM R11 List Control ATXUnicenter Asset Management+3 | 24/3/2008 | 16/6/2026 | Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of… | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Remotelyanywhere | 10/3/2008 | 16/6/2026 | The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted. | |
| Modificada | Alta (10) | 5.4% | — | Brooks Internet Software RPM Remote Print Manager EliteBrooks Internet Software RPM Remote Print Manager Select | 13/2/2008 | 16/6/2026 | Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.2) | 0.84% | 💥 Exploit | Safenet Ipsecdrv.sysSafenet Highassurance RemoteSafenet Softremote VPN Client | 5/2/2008 | 16/6/2026 | IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request. | |
| Modificada | Baja (1.9) | 0.30% | — | Data-vision Remotedocs R-viewer | 18/9/2007 | 16/6/2026 | RemoteDocs R-Viewer before 1.6.3768 stores encrypted RDZ file data in unencrypted temporary files, which allows local users to obtain sensitive information by reading the temporary files. | |
| Modificada | Alta (9.3) | 4.6% | — | Data-vision Remotedocs R-viewer | 18/9/2007 | 16/6/2026 | Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ archive in which the first file has an executable extension. | |
| Modificada | Media (4.3) | 1.5% | — | Dell Remote Access Card | 15/8/2007 | 16/6/2026 | Unspecified vulnerability in Dell Remote Access Card 4 (DRAC4) with firmware 1.50 Build 02.16 allows remote attackers to cause a denial of service (SSH daemon crash) via certain network traffic, as demonstrated by an "nmap -O" scan with nmap 4.03, possibly related to a Mocana (Mocanada) SSH vulnerability. | |
| Modificada | Alta (9.3) | 24% | — | Broadcom Advantage Data TransportBroadcom Brightstor PortalBroadcom Brightstor SAN ManagerBroadcom Cleverpath Aion+20 | 26/7/2007 | 16/6/2026 | Stack-based buffer overflow in the Message Queuing Server (Cam.exe) in CA (formerly Computer Associates) Message Queuing (CAM / CAFT) software before 1.11 Build 54_4 on Windows and NetWare, as used in CA Advantage Data Transport, eTrust Admin, certain BrightStor products, certain CleverPath products, and certain… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Safenet Highassurance RemoteSafenet Softremote VPN Client | 11/6/2007 | 16/6/2026 | IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related to the IPv6 support for IPSec. | |
| Modificada | Alta (7.8) | 4.3% | 💥 Exploit | Fruit2004 Remote Display Development KIT | 11/5/2007 | 16/6/2026 | Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of service (Internet Explorer 7 crash) via (1) a long first argument to the connect function or (2) a long InternalServer property value, possibly involving ntdll.dll. | |
| Modificada | Alta (7.2) | 0.65% | — | HP Power Manager Remote Agent | 30/4/2007 | 16/6/2026 | Unspecified vulnerability in the HP Power Manager Remote Agent (RA) 4.0Build10 and earlier in HP-UX B.11.11 and B.11.23 allows local users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Remotesoft .net Explorer | 6/2/2007 | 16/6/2026 | Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long line in a .cpp file. | |
| Modificada | Alta (7.2) | 0.33% | — | Apple Remote Desktop | 18/11/2006 | 16/6/2026 | Apple Remote Desktop before 3.1 uses insecure permissions for certain built-in packages, which allows local users on an Apple Remote Desktop administration system to modify the packages and gain root privileges on client systems that use the packages. | |
| Modificada | Baja (2.1) | 0.21% | — | Securecomputing Safeword Remoteaccess | 17/10/2006 | 16/6/2026 | Secure Computing SafeWord RemoteAccess 2.1 allows local users to obtain the UserCenter webportal password, database encryption keys, and signing keys by reading (1) base-64 encoded data in SERVERS\Web\Tomcat\usercenter\WEB-INF\login.conf and (2) plaintext data in SERVERS\Shared\signers.cfg. NOTE: the provenance of… | |
| Modificada | Alta (7.2) | 0.42% | — | Apple Remote DesktopApple MAC OS X | 19/9/2006 | 16/6/2026 | Apple Remote Desktop (ARD) for Mac OS X 10.2.8 and later does not drop privileges on the remote machine while installing certain applications, which allows local users to bypass authentication and gain privileges by selecting the icon during installation. NOTE: it could be argued that the issue is not in Remote… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Invisionix Systems Invisionix Roaming System Remote | 21/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter. | |
| Modificada | Alta (9) | 2.9% | — | Symantec Veritas Netbackup Puredisk Remote Office Edition | 18/8/2006 | 16/6/2026 | Symantec Veritas NetBackup PureDisk Remote Office Edition 6.0 before MP1 20060816 allows remote attackers to bypass authentication and gain privileges via unknown attack vectors in the management interface. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Phpremoteview | 17/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PRV.php in PhpRemoteView, possibly 2003-10-23 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) f, (2) d, and (3) ref parameters, and the (4) "MAKE DIR" and (5) "Full file name" fields. | |
| Modificada | Media (5) | 2.2% | — | Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote Agent | 19/3/2006 | 16/6/2026 | Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors." | |
| Modificada | Media (5) | 3.8% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection… | |
| Modificada | Media (5) | 12% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business… | |
| Modificada | Baja (2.1) | 0.34% | — | Avaya Vpnremote | 31/12/2005 | 16/6/2026 | Avaya VPNRemote before 4.2.33 stores credentials in cleartext in process memory, which allows attackers to obtain the VPN user's credentials. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Dameware Development Mini Remote Control Server | 8/9/2005 | 16/6/2026 | Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary code via the username. |