Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 6.8% | 💥 Exploit | Review-script.com Five Star Review Script | 19/6/2006 | 16/6/2026 | Varias vulnerabilidades de ejecución de comandos en sitios cruzados (XSS) en 5 Star Review permiten a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el parámetro sort en index2.php, (2) el parámetro item_id en report.php, (3) el parámetro SEARCH_TERM (que se trata del "cuadro de… | |
| Modificada | Media (5) | 1.8% | — | Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar | 25/2/2006 | 16/6/2026 | Directory traversal vulnerability in SpeedProject Squeez 5.1, as used in (1) ZipStar 5.1 and (2) SpeedCommander 11.01.4450, allows remote attackers to overwrite arbitrary files via unspecified manipulations in a (1) JAR or (2) ZIP archive. | |
| Modificada | Alta (7.2) | 0.34% | — | Starforce Safe N SEC Personal + Anti-spyware | 23/2/2006 | 16/6/2026 | Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious… | |
| Modificada | Media (5.1) | 4.0% | — | Njstar Chinese Word ProcessorNjstar Japanese Word Processor | 21/2/2006 | 16/6/2026 | Stack-based buffer overflow in NJStar Chinese and Japanese Word Processor 4.x and 5.x before 5.10 allows user-assisted attackers to execute arbitrary code via font names in NJStar (.njx) documents. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Estara Softphone | 17/2/2006 | 16/6/2026 | Multiple format string vulnerabilities in eStara SIP softphone allow remote attackers to cause a denial of service (hang) via SIP INVITE requests with format string specifiers in the SDP session description, as demonstrated using (1) the field name, (2) the o field (owner/creator and session identifier), or (3) the m… | |
| Modificada | Media (5) | 1.6% | — | Estara Softphone | 17/2/2006 | 16/6/2026 | eStara SIP softphone allows remote attackers to cause a denial of service (crash) via an INVITE request with a Content-Length field that has more than 9 digits. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Estara Softphone | 17/2/2006 | 16/6/2026 | eStara SIP softphone allows remote attackers to cause a denial of service (crash) via a SIP OPTIONS request with a negative Expires field. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Estara Softphone | 13/1/2006 | 16/6/2026 | Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060. | |
| Modificada | Media (4.3) | 1.2% | — | Starphire Technologies SitesageStarphire Technologies Sitesage-eeStarphire Technologies Sitesage-leStarphire Technologies Sitesage-sb+1 | 22/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Starphire SiteSage 5.0.18 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the norelay_highlight_words parameter. | |
| Modificada | Alta (7.8) | 4.3% | — | Astaro Security Linux | 4/12/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in Astaro Security Linux before 6.102 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory,… | |
| Modificada | Alta (7.5) | 1.3% | — | Omnistar Interactive Omnistar Kbase | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Omnistar Interactive Omnistar Live | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240. | |
| Modificada | Media (5.1) | 2.6% | — | Speedproject SpeedcommanderSpeedproject SqueezSpeedproject Zipstar | 26/11/2005 | 16/6/2026 | Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a… | |
| Modificada | Alta (7.5) | 1.5% | — | Utstarcom F1000 Voip Wifi Phone | 21/11/2005 | 16/6/2026 | The telnet daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has a default username "target" and password "password", which allows remote attackers to gain full access to the system. | |
| Modificada | Alta (7.5) | 2.2% | — | Utstarcom F1000 Voip Wifi Phone | 21/11/2005 | 16/6/2026 | UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 does not allow users to disable access to (1) SNMP or (2) the rlogin port TCP 513, which allows remote attackers to exploit other vulnerabilities such as CVE-2005-3716, or execute arbitrary shell commands via rlogin, which does not require… | |
| Modificada | Alta (7.5) | 1.6% | — | Utstarcom F1000 Wi-fi Firmware | 21/11/2005 | 16/6/2026 | The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Symantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System | 16/11/2005 | 16/6/2026 | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,… | |
| Modificada | Media (5) | 1.3% | — | 4D Webstar | 5/10/2005 | 16/6/2026 | Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2. | |
| Modificada | Media (5) | 1.8% | — | Astaro Security Linux | 28/9/2005 | 16/6/2026 | Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service. | |
| Modificada | Baja (2.1) | 0.81% | — | Astaro Security Linux | 30/8/2005 | 16/6/2026 | Directory traversal vulnerability in Astaro Security Linux 6.0, when using Webmin, allows remote authenticated webmin users to read arbitrary files via a .. (dot dot) in the wfe_download parameter to index.fpl. | |
| Modificada | Media (5) | 1.7% | — | Astaro Security Linux | 30/8/2005 | 16/6/2026 | The HTTP proxy in Astaro Security Linux 6.0 allows remote attackers to obtain sensitive information via an invalid request, which reveals a Proxy-authorization string in an error message. | |
| Modificada | Alta (7.5) | 6.6% | 💥 Exploit | Astaro Security Linux | 30/8/2005 | 16/6/2026 | The HTTP proxy in Astaro Security Linux 6.0 does not properly filter HTTP CONNECT requests to localhost, which allows remote attackers to bypass firewall rules and connect to local services. | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | 4D Webstar | 11/5/2005 | 16/6/2026 | Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL. | |
| Modificada | Media (5) | 4.3% | 💥 Exploit | Lucasarts Star Wars Jedi Knight Jedi Academy | 2/5/2005 | 16/6/2026 | Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. |