Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
–

722 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.3%—Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200r31/12/200216/6/2026
Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.
ModificadaAlta (7.5)1.3%—Symantec Norton Personal Firewall31/12/200216/6/2026
The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).
ModificadaAlta (7.8)1.7%—Symantec Velociraptor31/12/200216/6/2026
Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method.
ModificadaAlta (7.5)2.6%—Symantec Norton Antivirus31/12/200216/6/2026
NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue,…
ModificadaMedia (4.3)2.5%💥 ExploitSymantec Norton Personal Firewall31/12/200216/6/2026
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
ModificadaAlta (7.8)2.0%—Symantec Norton Antivirus31/12/200216/6/2026
The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries.
ModificadaMedia (5)1.9%—Symantec Enterprise FirewallSymantec Raptor FirewallSymantec Velociraptor31/12/200216/6/2026
Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not…
ModificadaMedia (5)14%—Microsoft Internet Information ServerMicrosoft Internet Information ServicesSymantec Norton Internet Security31/12/200216/6/2026
Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running.
ModificadaAlta (10)10%💥 ExploitSymantec Java31/12/200216/6/2026
Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler.
ModificadaAlta (7.5)2.6%—Symantec Norton Antivirus31/12/200216/6/2026
NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass the initial virus scan and cause NAV to prematurely stop scanning by using a non-RFC compliant MIME header. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed,…
ModificadaAlta (7.5)2.6%—Symantec Norton Antivirus31/12/200216/6/2026
NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to…
ModificadaAlta (7.5)2.6%—Symantec Norton Antivirus31/12/200216/6/2026
NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the…
ModificadaAlta (7.5)24%💥 ExploitOracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
El comando COM_CHANGE_USER en MySQL 3.x anteriores a 2.23.54 y 4.x anterior a 4.0.6 permite a atacantes remotos ejecutar código arbitrario mediante una respuesta larga.
ModificadaAlta (7.5)20%💥 ExploitOracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
El comando COM_CHANGE_USER en MySQL 3.x anterirores de 3.23.54 y 4.x anteriores a 4.0.5 permite a atacantes remotos ganar privilegios mediante un ataque de fuerza bruta usando una contraseña de un carácter, lo que hace que MySQL compare la contraseña suministrada sólo con el primer carácter de la contraseña real.
ModificadaAlta (7.5)6.8%—Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager23/12/200216/6/2026
La librería de cliente libmysqlclient en MySQL 3.x a 3.23.54 y 4.x a 4.06, no verifica adecuadamente longitudes de campos de ciertas respuestas en las rutinas read_rows o read_one_row, lo que permite a a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario.
ModificadaMedia (5)1.7%—Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security28/10/200216/6/2026
El componente de proxy web en Symantec Enterprise Firewall (SEF) 6.5.2 a 7.0, Raptor Firewall 6.5 y 6.5.3, VelociRaptor, y Symantec Gateway Security permite a atacantes remotos causar una denegación de servicio (agotamiento de recursos de conexiones) mediante múltiples peticiones de conexión a dominios cuyo servidor…
ModificadaMedia (5)1.8%—Symantec Veritas Backup Exec4/10/200216/6/2026
Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.
ModificadaAlta (7.5)1.5%—Symantec Norton Antivirus12/8/200216/6/2026
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.
ModificadaAlta (7.5)3.3%—Symantec Norton Internet SecuritySymantec Norton Personal Firewall26/7/200216/6/2026
Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request.
ModificadaAlta (7.5)1.7%—Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security3/7/200216/6/2026
FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability.
ModificadaMedia (5)2.8%—Symantec Liveupdate25/6/200216/6/2026
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.
ModificadaAlta (7.5)1.6%—Symantec Norton Ghost25/6/200216/6/2026
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.
ModificadaMedia (5)1.3%—Symantec Enterprise Firewall31/5/200216/6/2026
El demonio (daemon) de Symantec Enterprise Firewall 6.5.x deja caer importantes alertas cuando se usa SNMP como transporte, lo que podría impedir que algunas alertas se enviasen en caso de ataque.
ModificadaMedia (5)1.7%—Symantec Enterprise Firewall31/5/200216/6/2026
El proxy SMTP en Symantec Enterprise Firewall 6.5.x incluye el nombre y la dirección del interfaz físico del cortafuegos en un intercambio de mensajes SMTP cuando la traduzzión NAT (network address translation) se hace a una dirección distinta de la del cortafuegos, lo que podría permitir a atacantes remotos…
ModificadaMedia (5)2.6%—Symantec Liveupdate5/10/200116/6/2026
Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.