Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 336 respecto a la semana anterior
Críticas / altas1272▼ 222 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 108 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200r | 31/12/2002 | 16/6/2026 | Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password. | |
| Modificada | Alta (7.5) | 1.3% | — | Symantec Norton Personal Firewall | 31/12/2002 | 16/6/2026 | The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305). | |
| Modificada | Alta (7.8) | 1.7% | — | Symantec Velociraptor | 31/12/2002 | 16/6/2026 | Memory leak in the (1) httpd, (2) nntpd, and (3) vpn driver in VelociRaptor 1.0 allows remote attackers to cause a denial of service (memory consumption) via an unknown method. | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to bypass virus protection via a Word Macro virus with a .nch or .dbx extension, which is automatically recognized and executed as a Microsoft Office document. NOTE: the vendor has disputed this issue,… | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Symantec Norton Personal Firewall | 31/12/2002 | 16/6/2026 | Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. | |
| Modificada | Alta (7.8) | 2.0% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | The POP3 proxy service (POPROXY.EXE) in Norton AntiVirus 2001 allows local users to cause a denial of service (CPU consumption and crash) via a long username with multiple /localhost entries. | |
| Modificada | Media (5) | 1.9% | — | Symantec Enterprise FirewallSymantec Raptor FirewallSymantec Velociraptor | 31/12/2002 | 16/6/2026 | Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not… | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Information ServerMicrosoft Internet Information ServicesSymantec Norton Internet Security | 31/12/2002 | 16/6/2026 | Norton Internet Security 2001 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while Norton Internet Security is running. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Symantec Java | 31/12/2002 | 16/6/2026 | Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler. | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass the initial virus scan and cause NAV to prematurely stop scanning by using a non-RFC compliant MIME header. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed,… | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus (NAV) 2002 allows remote attackers to bypass e-mail scanning via a filename in the Content-Type field with an excluded extension such as .nch or .dbx, but a malicious extension in the Content-Disposition field, which is used by Outlook to… | |
| Modificada | Alta (7.5) | 2.6% | — | Symantec Norton Antivirus | 31/12/2002 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Symantec Norton AntiVirus 2002 allows remote attackers to send viruses that bypass the e-mail scanning via a NULL character in the MIME header before the virus. NOTE: the vendor has disputed this issue, acknowledging that the initial scan is bypassed, but the… | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anteriores a 2.23.54 y 4.x anterior a 4.0.6 permite a atacantes remotos ejecutar código arbitrario mediante una respuesta larga. | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anterirores de 3.23.54 y 4.x anteriores a 4.0.5 permite a atacantes remotos ganar privilegios mediante un ataque de fuerza bruta usando una contraseña de un carácter, lo que hace que MySQL compare la contraseña suministrada sólo con el primer carácter de la contraseña real. | |
| Modificada | Alta (7.5) | 6.8% | — | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | La librería de cliente libmysqlclient en MySQL 3.x a 3.23.54 y 4.x a 4.06, no verifica adecuadamente longitudes de campos de ciertas respuestas en las rutinas read_rows o read_one_row, lo que permite a a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario. | |
| Modificada | Media (5) | 1.7% | — | Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security | 28/10/2002 | 16/6/2026 | El componente de proxy web en Symantec Enterprise Firewall (SEF) 6.5.2 a 7.0, Raptor Firewall 6.5 y 6.5.3, VelociRaptor, y Symantec Gateway Security permite a atacantes remotos causar una denegación de servicio (agotamiento de recursos de conexiones) mediante múltiples peticiones de conexión a dominios cuyo servidor… | |
| Modificada | Media (5) | 1.8% | — | Symantec Veritas Backup Exec | 4/10/2002 | 16/6/2026 | Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares. | |
| Modificada | Alta (7.5) | 1.5% | — | Symantec Norton Antivirus | 12/8/2002 | 16/6/2026 | Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients. | |
| Modificada | Alta (7.5) | 3.3% | — | Symantec Norton Internet SecuritySymantec Norton Personal Firewall | 26/7/2002 | 16/6/2026 | Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request. | |
| Modificada | Alta (7.5) | 1.7% | — | Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security | 3/7/2002 | 16/6/2026 | FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability. | |
| Modificada | Media (5) | 2.8% | — | Symantec Liveupdate | 25/6/2002 | 16/6/2026 | Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. | |
| Modificada | Alta (7.5) | 1.6% | — | Symantec Norton Ghost | 25/6/2002 | 16/6/2026 | Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges. | |
| Modificada | Media (5) | 1.3% | — | Symantec Enterprise Firewall | 31/5/2002 | 16/6/2026 | El demonio (daemon) de Symantec Enterprise Firewall 6.5.x deja caer importantes alertas cuando se usa SNMP como transporte, lo que podría impedir que algunas alertas se enviasen en caso de ataque. | |
| Modificada | Media (5) | 1.7% | — | Symantec Enterprise Firewall | 31/5/2002 | 16/6/2026 | El proxy SMTP en Symantec Enterprise Firewall 6.5.x incluye el nombre y la dirección del interfaz físico del cortafuegos en un intercambio de mensajes SMTP cuando la traduzzión NAT (network address translation) se hace a una dirección distinta de la del cortafuegos, lo que podría permitir a atacantes remotos… | |
| Modificada | Media (5) | 2.6% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. |