Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 53% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438. | |
| Modificada | Media (6.8) | 3.6% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+8 | 20/3/2008 | 16/6/2026 | Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as… | |
| Modificada | Alta (7.5) | 2.5% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+4 | 22/2/2008 | 16/6/2026 | Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792. | |
| Modificada | Media (5.8) | 2.2% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+4 | 15/2/2008 | 16/6/2026 | Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Media (6) | 0.31% | — | Symantec Client SecuritySymantec Norton Antivirus | 16/7/2007 | 16/6/2026 | Unspecified vulnerability in the Real-time scanner (RTVScan) component in Symantec AntiVirus Corporate Edition 9.0 through 10.1 and Client Security 2.0 through 3.1, when the Notification Message window is enabled, allows local users to gain privileges via crafted code. | |
| Modificada | Media (4.6) | 0.36% | — | Symantec Client SecuritySymantec Norton Antivirus | 15/7/2007 | 16/6/2026 | Stack-based buffer overflow in the Internet E-mail Auto-Protect feature in Symantec AntiVirus Corporate Edition before 10.1, and Client Security before 3.1, allows local users to cause a denial of service (service crash) via a long (1) To, (2) From, or (3) Subject header in an outbound SMTP e-mail message. NOTE: the… | |
| Modificada | Media (6.9) | 1.1% | — | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 15/7/2007 | 16/6/2026 | Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt… | |
| Modificada | Alta (9.3) | 3.7% | — | F-secure Anti-virusF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server SecurityF-secure Internet Security+2 | 20/6/2007 | 16/6/2026 | Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive. | |
| Modificada | Alta (9) | 2.2% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 6/6/2007 | 16/6/2026 | Unspecified vulnerability in Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, allows attackers to "disable the authentication system" and bypass authentication via unknown… | |
| Modificada | Media (4.3) | 2.1% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, displays the password hash for a user after a failed login attempt, which makes it easier for remote attackers to conduct brute… | |
| Modificada | Alta (7.5) | 2.0% | — | Symantec Client SecuritySymantec Norton AntivirusSymantec Reporting Server | 5/6/2007 | 16/6/2026 | Symantec Reporting Server 1.0.197.0, and other versions before 1.0.224.0, as used in Symantec Client Security 3.1 and later, and Symantec AntiVirus Corporate Edition (SAV CE) 10.1 and later, does not initialize a critical variable, which allows attackers to create arbitrary executable files via unknown manipulations… | |
| Modificada | Alta (10) | 4.8% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+3 | 31/5/2007 | 16/6/2026 | Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files. | |
| Modificada | Alta (7.2) | 0.35% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+3 | 31/5/2007 | 16/6/2026 | Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request… | |
| Modificada | Alta (7.5) | 5.2% | — | F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+3 | 31/5/2007 | 16/6/2026 | Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335. | |
| Modificada | Media (4.9) | 1.7% | — | Symantec AntivirusSymantec Client SecuritySymantec Norton 360Symantec Norton Antispam+4 | 2/4/2007 | 16/6/2026 | SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2)… | |
| Modificada | Baja (1.9) | 0.86% | — | Symantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+2 | 16/3/2007 | 16/6/2026 | The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's… | |
| Modificada | Media (4.3) | 0.38% | — | Symantec Client SecuritySymantec Norton Antivirus | 23/10/2006 | 16/6/2026 | The SAVRT.SYS device driver, as used in Symantec AntiVirus Corporate Edition 8.1 and 9.0.x up to 9.0.3, and Symantec Client Security 1.1 and 2.0.x up to 2.0.3, allows local users to execute arbitrary code via a modified address for the output buffer argument to the DeviceIOControl function. | |
| Modificada | Media (6.4) | 1.3% | — | IBM Client Security Password Manager | 5/10/2006 | 16/6/2026 | IBM Client Security Password Manager stores and distributes saved passwords based upon the title of a website, which allows remote attackers to obtain username and password credentials by changing the title of an HTML page. | |
| Modificada | Media (4.9) | 1.3% | — | Symantec Client SecuritySymantec Host IDSSymantec Norton AntivirusSymantec Norton Internet Security+3 | 19/9/2006 | 16/6/2026 | The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5… | |
| Modificada | Media (4.6) | 0.45% | — | Symantec Client SecuritySymantec Norton Antivirus | 14/9/2006 | 16/6/2026 | Format string vulnerability in the Real Time Virus Scan service in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allows local users to execute arbitrary code via an unspecified vector related to alert notification messages, a different vector than CVE-2006-3454, a "second… | |
| Modificada | Alta (7.2) | 0.46% | — | Symantec Client SecuritySymantec Norton Antivirus | 14/9/2006 | 16/6/2026 | Multiple format string vulnerabilities in Symantec AntiVirus Corporate Edition 8.1 up to 10.0, and Client Security 1.x up to 3.0, allow local users to execute arbitrary code via format strings in (1) Tamper Protection and (2) Virus Alert Notification messages. |