Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 10% | 💥 Exploit | CA Internet Security Suite Plus 2008 | 2/6/2008 | 16/6/2026 | Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged… | |
| Modificada | Media (4.3) | 16% | — | Websense EnterpiseWebsense Reporting ToolsWebsense WEB Security Suite | 11/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Baja (2.1) | 0.31% | — | Ghostsecurity Ghost Security Suite | 24/9/2007 | 16/6/2026 | Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4)… | |
| Modificada | Baja (2.1) | 0.30% | — | Ghostsecurity Ghost Security Suite | 24/9/2007 | 16/6/2026 | Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtCreateThread, (3) NtDeleteValueKey, (4) NtQueryValueKey,… | |
| Modificada | Media (4.3) | 3.6% | — | Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+19 | 26/7/2007 | 16/6/2026 | arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file. | |
| Modificada | Alta (9.3) | 50% | 💥 Exploit | Broadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+9 | 6/6/2007 | 16/6/2026 | Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file. | |
| Modificada | Alta (9.3) | 8.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+19 | 8/2/2007 | 16/6/2026 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable. | |
| Modificada | Media (6.6) | 0.38% | — | Broadcom Etrust AntivirusBroadcom Internet Security Suite | 13/12/2006 | 16/6/2026 | The (1) VetMONNT.sys and (2) VetFDDNT.sys drivers in CA Anti-Virus 2007 8.1, Anti-Virus for Vista Beta 8.2, and CA Internet Security Suite 2007 v3.0 do not properly handle NULL buffers, which allows local users with administrative access to cause a denial of service (system crash) via certain IOCTLs. | |
| Modificada | Media (5) | 1.8% | — | Mcafee Internet Security SuiteMcafee Network AgentMcafee Personal Firewall PlusMcafee Virusscan | 20/10/2006 | 16/6/2026 | McAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus, and VirusScan, allows remote attackers to cause a denial of service (agent crash) via a long packet, possibly because of an invalid string position field value. NOTE:… | |
| Modificada | Alta (7.5) | 1.3% | — | Dimitri Seitz Security Suite IP Logger | 17/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Dimitri Seitz Security Suite IP Logger in dwingmods for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) mkb.php, (2) iplogger.php, (3) admin_board2.php, or (4) admin_logger.php in includes/, different… | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Dimitri Seitz Security Suite IP Logger | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands… | |
| Modificada | Media (4.9) | 0.63% | — | Zonelabs Zonealarm Security Suite | 13/7/2006 | 16/6/2026 | Check Point Zone Labs ZoneAlarm Internet Security Suite 6.5.722.000, 6.1.737.000, and possibly other versions do not properly validate RegSaveKey, RegRestoreKey, and RegDeleteKey function calls, which allows local users to cause a denial of service (system crash) via a certain combination of these function calls with… | |
| Modificada | Alta (7.2) | 0.36% | — | Trendmicro Interscan Messaging Security Suite | 24/3/2006 | 16/6/2026 | ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecure DACLs for critical files, which allows local users to gain SYSTEM privileges by modifying ISNTSysMonitor.exe. | |
| Modificada | Media (6.2) | 0.52% | — | Zonelabs Zonealarm Security Suite | 14/3/2006 | 16/6/2026 | Untrusted search path vulnerability in the TrueVector service (VSMON.exe) in Zone Labs ZoneAlarm 6.x and Integrity does not search ZoneAlarm's own folders before other folders that are specified in a user's PATH, which might allow local users to execute code as SYSTEM by placing malicious DLLs into a folder that has… | |
| Modificada | Media (5.1) | 1.9% | — | Trend Micro Interscan Messaging Security SuiteTrend Micro Interscan WEB Security SuiteTrend Micro Serverprotect | 10/2/2006 | 16/6/2026 | Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass… | |
| Modificada | Alta (7.2) | 0.35% | — | Checkpoint ZonealarmCheckpoint Zonealarm Security Suite | 31/12/2005 | 16/6/2026 | Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local users to gain privileges or bypass security controls. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Zonelabs ZonealarmZonelabs Zonealarm Anti-spywareZonelabs Zonealarm AntivirusZonelabs Zonealarm Security Suite | 16/11/2005 | 16/6/2026 | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs"… | |
| Modificada | Media (5.1) | 1.3% | — | Mcafee Internet Security Suite | 30/10/2005 | 16/6/2026 | Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally… | |
| Modificada | Alta (10) | 42% | — | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus PersonalKaspersky LAB Kaspersky Anti-virus Personal PROKaspersky LAB Kaspersky Personal Security Suite | 5/10/2005 | 16/6/2026 | Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header. | |
| Modificada | Alta (7.5) | 4.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+11 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure. | |
| Modificada | Alta (7.2) | 0.34% | — | Mcafee Internet Security Suite | 18/4/2005 | 16/6/2026 | McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files. |