Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

823 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.40%—Utstarcom Ian-02ex Voip ATA9/3/200516/6/2026
UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.
ModificadaAlta (7.5)1.5%—Outstart Participate Enterprise8/3/200516/6/2026
Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete…
ModificadaAlta (10)22%💥 ExploitXmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+21/3/200516/6/2026
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the…
ModificadaMedia (5)3.4%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.
ModificadaMedia (5)3.1%💥 ExploitLucasarts Star Wars Battlefront10/1/200516/6/2026
Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.
ModificadaMedia (6.4)1.7%—Xmlstarlet Command Line XML Toolkit31/12/200416/6/2026
Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code.
ModificadaMedia (5)4.2%—Sophos Astaro Security Linux31/12/200416/6/2026
The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks.
ModificadaMedia (5)2.1%—Astaro Security Linux31/12/200416/6/2026
The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks.
ModificadaAlta (10)2.0%—Xmlstarlet Command Line XML Toolkit31/12/200416/6/2026
Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c.
ModificadaAlta (7.2)0.43%—Joerg Schilling Star Tape Archiver23/12/200416/6/2026
Star anteriores a 1.5_alpha46 no libera la ID de usuario efectiva (euid) antes de llamar a programas externos, lo que podría permitir a usuarios locales ganar privilegios modificando la variable de entorno RSH para hacer referncia a programas maliciosos.
ModificadaMedia (5)7.2%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS.
ModificadaAlta (7.5)9.5%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo.
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio.
ModificadaMedia (5)1.4%—4D Webstar27/7/200416/6/2026
El script ShellExample.cgi en WebSTAR 5.3.2 y anteriores permite a un atacante remotos listar directorios arbitrarios mediante una URL con la ruta deseada y un carácter "*" (asterisco).
ModificadaBaja (3.6)0.34%—4D Webstar27/7/200416/6/2026
4D WebSTAR 5.3.2 y anteriores permiten a usuarios locales leer y modificar ficheros de su elección mediante una ataque de enlaces simbólicos.
ModificadaAlta (7.5)38%💥 Exploit4D Webstar27/7/200416/6/2026
Desbordamiento de búfer basado en la pila en el servicio FTP de 4D WebSTAR 5.3.2 y anteriores permite a atacantes remotos ejecutar código de su elección mediante un comando FTP largo.
ModificadaMedia (5)1.4%—4D Webstar27/7/200416/6/2026
Vulnerabilidad desconocida en 4D WebSTAR 5.3.2 y anteriores permite a atacantes remotos leer el fichero de configuración php.ini y posiblemente obtener información sensible.
ModificadaAlta (7.5)4.6%—Oracle JRESUN Java WEB StartSUN Jsse31/12/200316/6/2026
X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper…
ModificadaBaja (2.1)0.39%—Astart Technologies Lprng5/5/200316/6/2026
psbanner en el paquete LPRng permite a usuarios locales sobreescribir ficheros mediante un ataque de enlaces simbólicos en fichero /tmp/before
ModificadaMedia (5)8.1%💥 ExploitAstaware SearchdiscSunone Starter KIT2/4/200316/6/2026
Vulnerabilidad de atravesamiento de directorios en ASTAware SearchDisk engine en Sun ONE Starter Kit 2.0 permite a atacantes remotos leer ficheros arbitrarios mediante un ataque de .. (punto punto)en los puertos 6015 ó 6016, o una ruta absoluta en el puerto 6017
ModificadaAlta (7.5)1.5%—Utstarcom BAS 100031/12/200216/6/2026
UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of…
ModificadaBaja (2.1)0.38%—Astaro Security Linux31/12/200216/6/2026
Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files.
ModificadaAlta (7.5)1.8%—SUN Java WEB Start31/12/200216/6/2026
Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors.
ModificadaAlta (7.5)9.9%—ISC BindAstaro Security Linux29/11/200216/6/2026
Desbordamientos de búfer en la libreria de resolución de raíz DNS en ISC BIND 4.9.2 a 4.9.10, y otras librerías derivadas como BSD libc y GNU libc, permite a atacantes remotos ejecutar código arbitrario mediante respuestas de servidor DNS que disparan el desbordamiento en las funciones getnetbyname() y getnetbyaddr().…
ModificadaMedia (4.6)0.80%💥 ExploitEcartisListar12/8/200216/6/2026
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or…
Orbitaley — Vulnerabilidades