Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
943 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.5% | — | SUN Java System WEB Server | 13/7/2009 | 16/6/2026 | Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java WEB ConsoleSUN Solaris | 1/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.6% | — | SUN Java System Access Manager | 1/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 2.2% | — | SUN Java System WEB ServerSUN ONE WEB Server | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary web script or HTML via the query string in situations that result in a 502 Gateway error. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Portal Server | 26/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to an error page. | |
| Modificada | Media (4.3) | 5.3% | — | SUN Java System Communications Express | 21/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book… | |
| Modificada | Media (6.8) | 7.2% | — | SUN Java System Delegated Administrator | 23/4/2009 | 16/6/2026 | CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter. | |
| Modificada | Media (5) | 1.9% | — | SUN Java System Directory Server | 17/4/2009 | 16/6/2026 | The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors. | |
| Modificada | Media (5) | 8.7% | — | SUN Java System Calendar ServerSUN ONE Calendar Server | 1/4/2009 | 16/6/2026 | Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter. | |
| Modificada | Media (4.3) | 4.4% | — | SUN Java System Calendar ServerSUN ONE Calendar Server | 1/4/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to… | |
| Modificada | Alta (10) | 2.4% | — | Bouncycastle Bc-javaBouncycastle Bouncy-castle-crypto-package | 30/3/2009 | 16/6/2026 | The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed attributes." | |
| Modificada | Media (4.3) | 2.8% | — | SUN Java | 25/3/2009 | 16/6/2026 | The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing… | |
| Modificada | Alta (7.5) | 3.6% | — | SUN Java | 25/3/2009 | 16/6/2026 | The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490. | |
| Modificada | Media (5.8) | 2.2% | — | SUN Java | 25/3/2009 | 16/6/2026 | The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass… | |
| Modificada | Media (6.4) | 4.5% | — | SUN Java | 25/3/2009 | 16/6/2026 | Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to… | |
| Modificada | Media (6.4) | 4.6% | — | SUN Java | 25/3/2009 | 16/6/2026 | Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation." | |
| Modificada | Alta (7.5) | 5.7% | — | SUN Java Runtime EnvironmentSUN Java SE Development KIT | 25/3/2009 | 16/6/2026 | Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer… | |
| Modificada | Media (6.4) | 2.6% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object. | |
| Modificada | Alta (9) | 3.7% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters." | |
| Modificada | Alta (9) | 3.4% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and… | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033. | |
| Modificada | Media (4.3) | 2.0% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683. | |
| Modificada | Media (4) | 1.8% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact. | |
| Modificada | Media (6.5) | 2.5% | — | SUN Java System Identity Manager | 25/3/2009 | 16/6/2026 | The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password. |