Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

752 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio.
ModificadaAlta (7.5)5.9%—Checkpoint Firewall-1Checkpoint Vpn-128/9/200416/6/2026
Desbordamiento de búfer basado en el montón en la librería de decodificación ASN.1 de productos CheckPoint VPN-1, cuando se ha implementado IKE agresivo, permite a atacantes remotos ejecutar código de su elección iniciando una negociación IKE y enviando un paquete IKE con datos ASN.1 malformados.
ModificadaAlta (10)5.0%—Checkpoint Firewall-1Checkpoint Next GenerationCheckpoint Ng-aiCheckpoint Vpn-17/7/200416/6/2026
Desbordamiento de búfer en la funcionalidad ISAKMP de los productos Check Point VPN-1 y FireWall-1 NG, anteriores a VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 y NG FP3 HFA-325, o VPN-1 SecuRemote/SecureClient R56, puede permitir a atacantes remotos ejecutar código arbitrario mediane una negociación de tunel VPN.
ModificadaBaja (1.2)0.31%—Psionic Logcheck7/7/200416/6/2026
logcheck anteriores a 1.1.1 permite a usuarios locales sobreescribir ficheros de su eleccíón, posiblemente mediante un ataque de enlaces simbólicos (symlink) un directorio temporal en /var/tmp
ModificadaAlta (10)7.6%—Checkpoint Firewall-1Checkpoint Vpn-13/3/200416/6/2026
Desbordamiento de búfer basado en la pila en Checkpoint VPN-1 Server 4.1 a 4.1 SP6 y Checkpoint SecuRemote/SecureClient 4.1 a 4.1 compilación 4200 pemite a atacantes remotos ejecutar código arbitrario mediante un paquete ISAKMP con un paquete de Petición de Certificado muy grande.
ModificadaAlta (10)9.3%—Checkpoint Firewall-13/3/200416/6/2026
Múltiples vulnerabilidades de cadena de formato en el componente HTTP Application Intelligence (IA) de Checkpoint Firewall-1 NG-AI R55 y R54, y Checkpoint Firewall-1 HTTP Security Server incluido con NG FP1, FP2, y FP3 permite a atacantes remotos ejecutar código arbitrario mediante peticiones HTTP que hacen que se…
ModificadaMedia (5)2.8%💥 ExploitCheckpoint Firewall-120/10/200316/6/2026
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
ModificadaAlta (7.5)8.7%💥 ExploitSymantec Security Check7/8/200316/6/2026
Desbordamiento de búfer en el control ActiveX "RuFSI Utility Class" (tambien llamado "RuFSI Registry Information Class"), usado en el servicio Symantec Security Check, permite a atacantes remotos ejecutar código arbitrario mediante un argumento largo a CompareVersionStrings
ModificadaMedia (4.9)0.85%—Checkpoint Firewall-131/12/200216/6/2026
Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through the firewall.
ModificadaMedia (5)49%—Checkpoint Vpn-1 Firewall-131/12/200216/6/2026
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2)…
ModificadaAlta (10)2.6%—Pascal Michaud ASP Client Check31/12/200216/6/2026
SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.
ModificadaMedia (4.3)1.0%—Gabriele Bartolini HT Check28/10/200216/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (Cross-site scripting, XSS) en el interfaz PHP de ht://Check 1.1 permite a servidores web remotos insertar HTML arbitrario, incluyendo scripts, mediante una página web.
ModificadaAlta (7.5)1.6%—Checkpoint Check Point VPNCheckpoint Firewall-1Checkpoint Next Generation12/8/200216/6/2026
Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.
ModificadaAlta (7.2)0.34%—Checkpoint Firewall-11/4/200216/6/2026
Chek Point Firewall-1 3.0b a 4.0 SP1 sigue enlaces simbólicos y crea un fichero temporal .cpp escribible por todos los usuarios cuando compila las reglas de seguridad, lo que permite a un usuario local obtener privilegios o modificar la política del web.
ModificadaMedia (5)1.5%—Checkpoint Vpn-131/12/200116/6/2026
Check Point VPN-1 4.1SP4 using SecuRemote returns different error messages for valid and invalid users, with prompts that vary depending on the authentication method being used, which makes it easier for remote attackers to conduct brute force attacks.
ModificadaMedia (5)1.3%—Checkpoint Firewall-1Checkpoint Vpn-1Nokia Firewall Appliance8/10/200116/6/2026
Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way…
ModificadaAlta (7.5)3.9%—Checkpoint Firewall-121/9/200116/6/2026
Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name.
ModificadaMedia (6.4)1.5%—Checkpoint Firewall-18/9/200116/6/2026
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.
ModificadaMedia (6.2)0.30%—Checkpoint Firewall-18/9/200116/6/2026
Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.
ModificadaMedia (5)1.3%—Checkpoint Firewall-131/8/200116/6/2026
Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.
ModificadaMedia (5.5)0.21%—Checkpoint Zonealarm PROZonelabs Zonealarm29/8/200116/6/2026
ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.
ModificadaMedia (5)8.8%💥 ExploitCheckpoint Firewall-118/7/200116/6/2026
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.
ModificadaAlta (7.5)2.8%—Checkpoint Firewall-1Checkpoint Provider-1Checkpoint Vpn-112/7/200116/6/2026
Format string vulnerability in Check Point VPN-1/FireWall-1 4.1 allows a remote authenticated firewall administrator to execute arbitrary code via format strings in the control connection.
ModificadaAlta (7.5)3.2%—Checkpoint Firewall-19/7/200116/6/2026
Check Point VPN-1/FireWall-1 4.1 base.def contains a default macro, accept_fw1_rdp, which can allow remote attackers to bypass intended restrictions with forged RDP (internal protocol) headers to UDP port 259 of arbitrary hosts.
ModificadaMedia (5)1.3%—Thenet Checkbo2/7/200116/6/2026
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.