Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.3%—Siemens Speedstream Wireless Router27/7/200616/6/2026
Siemens SpeedStream 2624 permite a atacantes remotos provocar denegación de servicio (cuelgue de dispositivo) a través del envío de paquetes manipulados en el interface web del administrador.
ModificadaAlta (7.5)1.6%—Siemens Speedstream Wireless Router3/7/200616/6/2026
Vulnerabilidad en el router Speedstream Wireless 2624 de Siemens permite a usuarios locales evitar la autenticación y acceder a ficheros protegidos a través del componente Universal Plug and Play UPnP/1.0.
ModificadaAlta (7.5)3.6%—Lksctp Stream Control Transmission ProtocolCanonical Ubuntu Linux9/5/200616/6/2026
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
ModificadaMedia (5)3.8%—Lksctp Stream Control Transmission Protocol9/5/200616/6/2026
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (infinite recursion and crash) via a packet that contains two or more DATA fragments, which causes an skb pointer to refer back to itself when the full message is reassembled, leading to infinite recursion in the sctp_skb_pull…
ModificadaAlta (7.8)4.3%—Lksctp Stream Control Transmission Protocol9/5/200616/6/2026
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.
ModificadaMedia (4.3)1.2%—Epistream Ipei Guestbook31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 1.7 allows remote attackers to inject arbitrary web script or HTML via the email parameter, as used by the email field, when signing a guestbook.
ModificadaMedia (5)3.4%💥 ExploitInnovateware Sights N Sounds Streaming Media Server13/12/200516/6/2026
Desbordamiento de búfer en MediaServerList.exe en Sights 'n Sounds Streaming Media Server 2.0.3.a permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante una cadena de consulta larga.
ModificadaMedia (5)3.1%💥 ExploitGrandstream Budgetone 101Grandstream Budgetone 10216/8/200516/6/2026
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.
ModificadaMedia (5)1.6%—Apple Darwin Streaming Server18/7/200516/6/2026
Apple Darwin Streaming Server 5.5 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante una URL con un nombre de fichero con extensión .cgi y nombre de dispositivo de MS-DOS (tal como AUX, CON, PRN, COM1, o LPT1).
ModificadaAlta (7.5)1.2%—Grandstream Bt-100 Firmware11/7/200516/6/2026
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
ModificadaAlta (10)1.4%—Flexcast Audio Video Streaming Server9/6/200516/6/2026
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.
ModificadaAlta (7.5)1.7%—Fastream Netfile FTP WEB Server18/5/200516/6/2026
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service.
ModificadaMedia (5)1.3%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server10/1/200516/6/2026
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
ModificadaAlta (7.8)4.1%💥 ExploitFastream Netfile Server31/12/200416/6/2026
Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests.
ModificadaAlta (7.5)1.9%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server3/12/200416/6/2026
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
ModificadaBaja (2.1)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.
ModificadaAlta (7.5)3.4%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
ModificadaAlta (7.5)1.7%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
ModificadaBaja (2.1)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
ModificadaMedia (5)1.6%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
ModificadaBaja (2.1)0.35%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
ModificadaMedia (4.6)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.
ModificadaMedia (5)1.2%—Fastream Netfile FTP WEB Server6/8/200416/6/2026
Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A").
ModificadaAlta (10)4.3%💥 ExploitFastream Netfile FTP WEB Server6/8/200416/6/2026
Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter.
ModificadaMedia (5)2.0%—Fastream Netfile FTP WEB Server19/4/200416/6/2026
Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist.