Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.9% | — | SUN Java System Communications Express | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to affect integrity via unknown vectors related to Web Mail. | |
| Modificada | Media (6.8) | 2.3% | — | Oracle OpenssoSUN Java System Access Manager | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (5.7) | 0.34% | — | Oracle Glassfish ServerOracle Java System Message Queue | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle GlassFish 2.1, 2.1.1, and 3.0.1, and Java System Message Queue 4.1 allows local users to affect confidentiality, integrity, and availability, related to Java Message Service (JMS). | |
| Modificada | Baja (1) | 0.29% | — | SUN Java System Portal Server | 19/1/2011 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Portal Server 7.1 and 7.2 allows local users to affect confidentiality via unknown vectors related to Proxy. | |
| Modificada | Baja (2.4) | 0.27% | — | Oracle Java System Application ServerOracle Glassfish Server | 13/7/2010 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Application Server 8.0, 8.1, and 8.2; and GlassFish Enterprise Server 2.1.1; allows local users to affect confidentiality and integrity, related to the GUI. | |
| Modificada | Media (5.8) | 1.5% | — | Oracle SUN Java System WEB Proxy Server | 13/7/2010 | 16/6/2026 | Unspecified vulnerability in Oracle Sun Java System Web Proxy Server 4.0.13 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration Server. | |
| Modificada | Media (5) | 2.6% | — | Frederico Caldeira Knabben Fckeditor.java | 26/5/2010 | 16/6/2026 | FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters. | |
| Modificada | Media (6.8) | 3.4% | — | Apple Java 1.5Apple Java 1.6 | 21/5/2010 | 16/6/2026 | Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted applet. | |
| Modificada | Media (6.8) | 3.5% | — | Apple Java | 21/5/2010 | 16/6/2026 | Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Update 2 do not properly handle mediaLibImage objects, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted applet, related to the… | |
| Modificada | Alta (9.3) | 3.1% | — | Hitachi Ucosminexus/opentp1 WEB WEB Front-endsetHitachi Ucosminexus Application ServerHitachi Ucosminexus ClientHitachi Ucosminexus Collaboration+21 | 21/4/2010 | 16/6/2026 | Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF… | |
| Modificada | Alta (10) | 9.4% | — | SUN Java | 20/4/2010 | 16/6/2026 | Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business JDK and JRE 6 Update 18 and 19 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Communications Express | 1/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF)… | |
| Modificada | Media (5) | 2.2% | — | SUN Java System Directory Server | 25/2/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP… | |
| Modificada | Media (5) | 1.7% | — | SUN Java System WEB Server | 25/1/2010 | 16/6/2026 | The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token. | |
| Modificada | Alta (7.5) | 7.2% | — | SUN Java System WEB Server | 25/1/2010 | 16/6/2026 | Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND… | |
| Modificada | Alta (7.5) | 7.7% | — | SUN Java System WEB Server | 25/1/2010 | 16/6/2026 | Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header. | |
| Modificada | Alta (8.1) | 1.7% | — | SUN Java System Application Server | 25/1/2010 | 16/6/2026 | The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398. | |
| Modificada | Alta (10) | 80% | — | SUN Java System WEB Server | 20/1/2010 | 16/6/2026 | Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request. | |
| Modificada | Alta (10) | 3.1% | — | SUN Java System WEB Server | 20/1/2010 | 16/6/2026 | Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and… | |
| Modificada | Media (5) | 8.9% | — | SUN Java System Directory Server | 14/1/2010 | 16/6/2026 | The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message. | |
| Modificada | Media (6.8) | 2.2% | — | SUN Java System Identity Server | 14/1/2010 | 16/6/2026 | Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | SUN Java System WEB Server | 8/1/2010 | 16/6/2026 | Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information.… | |
| Modificada | Alta (7.5) | 2.5% | — | SUN Java System WEB Server | 8/1/2010 | 16/6/2026 | Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the… | |
| Modificada | Media (4.3) | 2.1% | — | SUN Java System Directory Server | 28/12/2009 | 16/6/2026 | Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allows remote attackers to cause a denial of service (psearch outage) by using a crafted psearch client to send requests that trigger a… | |
| Modificada | Media (5) | 2.5% | — | SUN Java System Directory Server | 28/12/2009 | 16/6/2026 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no… |