Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.3% | — | 3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master ControllerSoftmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified… | |
| Modificada | Alta (9) | 2.8% | — | HP Storageworks Modular Smart Array P2000 G3 Firmware | 17/12/2010 | 16/6/2026 | HP StorageWorks Modular Smart Array P2000 G3 firmware TS100R011, TS100R025, TS100P002, TS200R005, TS201R014, and TS201R015 installs an undocumented admin account with a default "!admin" password, which allows remote attackers to gain privileges. | |
| Modificada | Alta (9) | 2.0% | — | SUN Integrated Lights-out ManagerSUN Blade 6000 Modular System With ChassisSUN Blade 6048 Modular System With ChassisSUN Blade 8000 Modular System+33 | 23/10/2008 | 16/6/2026 | Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the service processor (SP) and cause a denial of service (shutdown or reboot), or (2) access the host operating system and have an unspecified impact, via unknown vectors. | |
| Modificada | Media (4.9) | 0.34% | — | Novell Modular Authentication Service | 12/6/2007 | 16/6/2026 | NMASINST in Novell Modular Authentication Service (NMAS) 3.1.2 and earlier on NetWare logs its invoking command line to NMASINST.LOG, which might allow local users to obtain the admin username and password by reading this file. | |
| Modificada | Media (5) | 1.7% | — | Modular Merchant Shopping Cart | 7/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in category.php in Modular Merchant Shopping Cart allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (5) | 2.4% | — | Avaya Modular Messaging Message Storage Server | 22/12/2005 | 16/6/2026 | POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets. | |
| Modificada | Baja (2.1) | 1.3% | 💥 Exploit | Award Bios ModularAI | 11/12/2005 | 16/6/2026 | AWARD Bios Modular 4.50pg does not clear the keyboard buffer after reading the BIOS password during system startup, which allows local administrators or users to read the password directly from physical memory. | |
| Modificada | Media (6.2) | 2.9% | 💥 Exploit | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+16 | 14/4/2005 | 16/6/2026 | Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor. | |
| Modificada | Baja (2.1) | 0.51% | — | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+11 | 14/4/2005 | 16/6/2026 | The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+3 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability." | |
| Modificada | Media (5) | 49% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+3 | 23/12/2004 | 16/6/2026 | Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability." | |
| Modificada | Alta (7.5) | 57% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+3 | 23/12/2004 | 16/6/2026 | Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string,… | |
| Modificada | Alta (7.5) | 6.3% | — | Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+15 | 21/12/2004 | 16/6/2026 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. | |
| Modificada | Media (5) | 34% | — | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+14 | 18/8/2004 | 16/6/2026 | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by… | |
| Modificada | Media (5) | 16% | — | Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header. | |
| Modificada | Alta (10) | 45% | — | Avaya Ip600 Media ServersAvaya Definity ONE Media ServerAvaya S8100Avaya Modular Messaging Message Storage Server+7 | 6/8/2004 | 16/6/2026 | Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041. | |
| Modificada | Alta (7.2) | 0.42% | — | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool. | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program. | |
| Modificada | Alta (7.2) | 24% | — | Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEAvaya Definity ONE Media ServerAvaya S8100+4 | 6/8/2004 | 16/6/2026 | Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share. | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. |