Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
752 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.0% | — | Checkpoint WEB Intelligence | 16/5/2007 | 16/6/2026 | CheckPoint Web Intelligence no maneja adecuadamente determinadas codificaciones de caracteres Unicode de ancho completo y medio, lo cual podría permitir a atacantes remotos evadir la detección de tráfico HTTP. | |
| Modificada | Alta (7.2) | 0.41% | — | Checkpoint Zonealarm | 24/4/2007 | 16/6/2026 | el manejo de IOCTL en srescan.sys en el ZoneAlarm Spyware Removal Engine (SRE) de Check Point ZoneAlarm anterior a 5.0.156.0 permite a usuarios locales ejecutar código de su elección a través de determinadas direcciones de parámetros lrp IOCTL. | |
| Modificada | Alta (7.5) | 1.5% | — | Distributed Checksum Clearinghouse DCC | 21/2/2007 | 16/6/2026 | Vulnerabilidad no especificada en Distributed Checksum Clearinghouse (DCC) anterior a 1.3.51 permite a atacantes remotos borrar o añadir anfitriones (hosts) en /var/dcc/maps. | |
| Rechazada | Sin puntuar | — | — | Checkpoint Firewall-1AI | 4/2/2007 | 7/11/2023 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is solely about a configuration that does not directly introduce security vulnerabilities, so it is more appropriate to cover under the Common Configuration Enumeration (CCE). In addition, it describes standard behavior… | |
| Modificada | Alta (7.5) | 2.7% | — | Checkpoint Connectra NGX | 24/1/2007 | 16/6/2026 | El archivo sre/params.php en el componente Integrity Clientless Security (ICS) en Check Point Connectra NGX R62 versión 3.x y anteriores a Security Hotfix versión 5, y posiblemente VPN-1 NGX R62, permite a los atacantes remotos omitir los requisitos de seguridad por medio de un parámetro Report creado, que devuelve un… | |
| Modificada | Alta (10) | 1.4% | — | Paessler Ipcheck Server Monitor | 31/8/2006 | 16/6/2026 | Paessler IPCheck Server Monitor anterior a 5.3.3.639/640 no implementa adecuadamente una "lista de direcciones IP de hosts aceptables en la configuración de sondeo", lo cual tiene impacto y vectores de ataque desconocidos. | |
| Modificada | Media (5) | 4.4% | 💥 Exploit | Ipcheck Server Monitor | 14/8/2006 | 16/6/2026 | Vulnerabilidad de salto de directorios en IPCheck Server Monitor anterior 5.3.3.639/640 permite a un atacante remoto leer archivos de su elección a través de la secuencia modificada .. (punto punto) en la URL, incluyendo (1) "..%2f" (codificación "/" barra), "..../" (multiples puntos), y "..%255c../"… | |
| Modificada | Media (5) | 3.5% | — | Checkpoint Firewall-1 | 27/7/2006 | 16/6/2026 | Vulnerabilidad de salto de directorio en Check Point Firewall-1 R55W anterior a HFA03 permite a atacantes remotos leer archivos de su elección mediante un .. (punto punto) codificado en el URL en el puerto TCP 18264. | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Cescripts Event Registration 2checkoutCescripts Event Registration CorporateCescripts Event Registration PaypalCescripts Event Registration Rsvp | 16/6/2006 | 16/6/2026 | Vulnerabilidad de ejecución de comandos en sitios cruzados (Cross-site scripting (XSS)) en el Registro de Eventos (Event Registration) que permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) event_id para ver-evento-details.php o (2) el parámetro select_events para… | |
| Modificada | Media (6.4) | 1.2% | 💥 Exploit | PHP Arena Pacheckbook | 5/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third… | |
| Modificada | Media (4.3) | 1.2% | — | Webcheck | 20/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report. | |
| Modificada | Alta (7.2) | 0.34% | — | Checkpoint Vpn-1 | 18/1/2006 | 16/6/2026 | Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program. | |
| Modificada | Alta (7.2) | 0.35% | — | Checkpoint ZonealarmCheckpoint Zonealarm Security Suite | 31/12/2005 | 16/6/2026 | Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local users to gain privileges or bypass security controls. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Checkpoint Secureclient NGCheckpoint Vpn-1 Secureclient | 8/12/2005 | 16/6/2026 | Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint. | |
| Modificada | Alta (7.8) | 4.9% | — | Checkpoint Check PointCheckpoint ExpressCheckpoint Firewall-1Checkpoint Vpn-1+1 | 18/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666,… | |
| Modificada | Alta (7.5) | 2.3% | — | Checkpoint Connectra NGX | 14/9/2005 | 16/6/2026 | Check Point NGX R60 does not properly verify packets against the predefined service group "CIFS" rule, which allows remote attackers to bypass intended restrictions. | |
| Modificada | Alta (7.2) | 0.41% | — | Checkpoint Securemote NGAI | 19/7/2005 | 16/6/2026 | Check Point SecuRemote NG with Application Intelligence R54 permite que atacantes obtengan credenciales y ganen privilegios mediante formas de ataque desconocidas. | |
| Modificada | Media (5) | 1.7% | — | Serverscheck Monitoring Software | 29/5/2005 | 16/6/2026 | Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request. | |
| Modificada | Baja (2.1) | 0.32% | — | Krzysztof Dabrowski Cmd5checkpw | 25/2/2005 | 16/6/2026 | cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file. | |
| Modificada | Baja (2.1) | 0.33% | — | Checkpoint Check Point Integrity ClientZonelabs ZonealarmZonelabs Zonealarm Wireless Security | 11/2/2005 | 16/6/2026 | vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause… | |
| Modificada | Alta (10) | 9.6% | — | Checkmark PayrollCheckmark MultiledgerInnermedia Dynazip LibraryRealnetworks Realone Player+1 | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en el archivo InnerMedia DynaZip DUNZIP32.dll versión 5.00.03 y anteriores permite a atacantes ejecutar código de su elección mediante un fichero ZIP con un nombre de fichero largo, como se a demostrado usando (1) un fichero .rjs (piel) en RealPlayer 10 a 10.5 (6.0.12.1053) y RealOne Player 1 y… | |
| Modificada | Alta (7.8) | 1.5% | — | Checkpoint Firewall-1 | 31/12/2004 | 16/6/2026 | Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Symantec Security Check Virus Detection | 31/12/2004 | 16/6/2026 | rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. |