Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.5% | — | SUN Java System Directory Server | 28/12/2009 | 16/6/2026 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable the SO_KEEPALIVE socket option, which makes it easier for remote attackers to cause a denial of service (connection slot exhaustion) via multiple connections, aka Bug Id 6782659. | |
| Modificada | Media (6.8) | 1.6% | — | SUN Java System Directory Server | 28/12/2009 | 16/6/2026 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by… | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Portal Server | 3/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 4.8% | — | Javascript Xerver Http Server | 29/11/2009 | 16/6/2026 | CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 2.5% | — | SUN Java System WEB Server | 5/11/2009 | 16/6/2026 | Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12. NOTE: as of 20091105, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable… | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Runtimes FOR Java Technology | 3/11/2009 | 16/6/2026 | Unspecified vulnerability in the XML component in IBM Runtimes for Java Technology 5.0.0 before SR10 has unknown impact and attack vectors, related to the "updated version of XML4J 4.4.17." | |
| Modificada | Media (6.8) | 2.3% | — | Apple MAC OS XApple MAC OS X ServerApple Java 1.4Apple Java 1.5+1 | 9/9/2009 | 16/6/2026 | Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. | |
| Modificada | Alta (9.3) | 1.6% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a "3Y Race condition in reflection checks." | |
| Modificada | Alta (10) | 2.7% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, aka BugId 6444262. | |
| Modificada | Alta (10) | 2.8% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6429594. NOTE: this issue exists because of an incorrect fix for BugId 6406003. | |
| Modificada | Alta (10) | 2.4% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6406003. | |
| Modificada | Media (5) | 2.0% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException in the Jemmy library) via unknown vectors. | |
| Modificada | Media (5) | 2.0% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching… | |
| Modificada | Media (6.8) | 1.7% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. | |
| Modificada | Media (6.8) | 1.3% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. | |
| Modificada | Alta (7.5) | 1.3% | — | SUN Java SE | 10/8/2009 | 16/6/2026 | The plugin functionality in Sun Java SE 6 before Update 15 does not properly implement version selection, which allows context-dependent attackers to leverage vulnerabilities in "old zip and certificate handling" and have unspecified other impact via unknown vectors. | |
| Modificada | Media (5) | 2.6% | — | SUN Java SESUN Openjdk | 10/8/2009 | 16/6/2026 | The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application. | |
| Modificada | Alta (10) | 2.8% | — | SUN Java SESUN Openjdk | 10/8/2009 | 16/6/2026 | JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an untrusted (1) applet or (2) application. | |
| Modificada | Alta (10) | 2.9% | — | SUN Java SESUN Openjdk | 10/8/2009 | 16/6/2026 | The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrection to obtain a reference to a privileged object. | |
| Modificada | Alta (7.8) | 2.3% | — | SUN Java SESUN Openjdk | 10/8/2009 | 16/6/2026 | Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, might allow context-dependent attackers to obtain sensitive information via vectors involving static variables that are declared without the final keyword, related to (1) LayoutQueue, (2) Cursor.predefined, (3) AccessibleResourceBundle.getContents,… | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Access ManagerSUN Java System WEB Server | 7/8/2009 | 16/6/2026 | The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.37% | — | SUN Java System Access ManagerSUN Java System WEB ServerSUN Opensso Enterprise | 7/8/2009 | 16/6/2026 | Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files. | |
| Modificada | Media (5) | 30% | — | Oracle JDKFedoraproject FedoraOpensuseSuse Linux Enterprise Server+5 | 6/8/2009 | 16/6/2026 | XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the… | |
| Modificada | Media (6.8) | 3.6% | — | SUN Java SESUN JDKSUN JRESUN SDK | 5/8/2009 | 16/6/2026 | Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an… | |
| Modificada | Alta (7.8) | 2.5% | — | SUN Java System Access Manager Policy Agent | 27/7/2009 | 16/6/2026 | The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request. |