Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2823▼ 249 respecto a la semana anterior
Críticas / altas1318▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

713 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)4.5%—Broadcom Mlink5/4/200216/6/2026
Buffer overflows in Computer Associates MLink (CA-MLink) 6.5 and earlier may allow local users to execute arbitrary code via long command line arguments to (1) mlclear or (2) mllock.
ModificadaAlta (10)3.4%—Broadcom Arcserve BackupBroadcom Arcserve Backup 2000CA Arcserve Backup 200015/9/200116/6/2026
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 stores the backup agent user name and password in cleartext in the aremote.dmp file in the ARCSERVE$ hidden share, which allows local and remote attackers to gain privileges.
ModificadaMedia (6.4)3.0%—Broadcom Arcserve BackupBroadcom Arcserve Backup 2000CA Arcserve Backup 200015/9/200116/6/2026
Computer Associates ARCserve for NT 6.61 SP2a and ARCserve 2000 7.0 creates a hidden share named ARCSERVE$, which allows remote attackers to obtain sensitive information and overwrite critical files.
ModificadaAlta (7.2)0.42%—Broadcom Inoculateit22/8/200116/6/2026
ftpdownload in Computer Associates InoculateIT 6.0 allows a local attacker to overwrite arbitrary files via a symlink attack on /tmp/ftpdownload.log .
ModificadaAlta (7.5)1.3%—Broadcom CCC Harvest18/6/200116/6/2026
Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.
ModificadaBaja (1.2)0.61%💥 ExploitBroadcom Arcserve BackupCA Arcserve Backup18/5/200116/6/2026
Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.
ModificadaAlta (7.5)2.4%💥 ExploitBroadcom Inoculateit Agent FOR Exchange31/12/200023/9/2026
Computer Associates InoculateIT Agent para Exchange Servidor no reconoce un archivo adjunto de virus de correo electrónico si la cabecera SMTP carece del campo 'From', lo que permite a atacantes remotos eludir la protección antivirus.
ModificadaAlta (10)6.1%—Broadcom Etrust Access ControlCA Etrust Access Control20/10/200016/6/2026
The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.
ModificadaBaja (2.1)0.51%💥 ExploitBroadcom Etrust Intrusion Detection7/6/200016/6/2026
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.
ModificadaAlta (7.5)1.5%—Broadcom Inoculateit12/5/199916/6/2026
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.
ModificadaAlta (10)1.7%—Broadcom Arcserve Backup21/2/199916/6/2026
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.
ModificadaMedia (5)1.8%—Broadcom Controlit1/1/199916/6/2026
Local or remote users can force ControlIT 4.5 to reboot or force a user to log out, resulting in a denial of service.
ModificadaMedia (4.6)1.5%—Broadcom Arcserve BackupBroadcom InoculanMicrosoft Exchange Server12/11/199816/6/2026
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.