Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
823 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.40% | — | Utstarcom Ian-02ex Voip ATA | 9/3/2005 | 16/6/2026 | UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset. | |
| Modificada | Alta (7.5) | 1.5% | — | Outstart Participate Enterprise | 8/3/2005 | 16/6/2026 | Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject parameter to renamepopup.jsp, (3) delete… | |
| Modificada | Alta (10) | 22% | 💥 Exploit | Xmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+2 | 1/3/2005 | 16/6/2026 | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the… | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory. | |
| Modificada | Media (6.4) | 1.7% | — | Xmlstarlet Command Line XML Toolkit | 31/12/2004 | 16/6/2026 | Format string vulnerability in xml_elem.c for XMLStarlet Command Line XML Toolkit 0.9.3 may allow attackers to cause a denial of service or execute arbitrary code. | |
| Modificada | Media (5) | 4.2% | — | Sophos Astaro Security Linux | 31/12/2004 | 16/6/2026 | The firewall in Astaro Security Linux before 4.024 sends responses to SYN-FIN packets, which makes it easier for remote attackers to obtain information about the system and construct specialized attacks. | |
| Modificada | Media (5) | 2.1% | — | Astaro Security Linux | 31/12/2004 | 16/6/2026 | The PPTP server in Astaro Security Linux before 4.024 provides information about its version, which makes it easier for remote attackers to construct specialized attacks. | |
| Modificada | Alta (10) | 2.0% | — | Xmlstarlet Command Line XML Toolkit | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in XMLStarlet Command Line XML Toolkit 0.9.3 have unknown impact and attack vectors via (1) xml_elem.c and (2) xml_select.c. | |
| Modificada | Alta (7.2) | 0.43% | — | Joerg Schilling Star Tape Archiver | 23/12/2004 | 16/6/2026 | Star anteriores a 1.5_alpha46 no libera la ID de usuario efectiva (euid) antes de llamar a programas externos, lo que podría permitir a usuarios locales ganar privilegios modificando la variable de entorno RSH para hacer referncia a programas maliciosos. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Media (5) | 1.4% | — | 4D Webstar | 27/7/2004 | 16/6/2026 | El script ShellExample.cgi en WebSTAR 5.3.2 y anteriores permite a un atacante remotos listar directorios arbitrarios mediante una URL con la ruta deseada y un carácter "*" (asterisco). | |
| Modificada | Baja (3.6) | 0.34% | — | 4D Webstar | 27/7/2004 | 16/6/2026 | 4D WebSTAR 5.3.2 y anteriores permiten a usuarios locales leer y modificar ficheros de su elección mediante una ataque de enlaces simbólicos. | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | 4D Webstar | 27/7/2004 | 16/6/2026 | Desbordamiento de búfer basado en la pila en el servicio FTP de 4D WebSTAR 5.3.2 y anteriores permite a atacantes remotos ejecutar código de su elección mediante un comando FTP largo. | |
| Modificada | Media (5) | 1.4% | — | 4D Webstar | 27/7/2004 | 16/6/2026 | Vulnerabilidad desconocida en 4D WebSTAR 5.3.2 y anteriores permite a atacantes remotos leer el fichero de configuración php.ini y posiblemente obtener información sensible. | |
| Modificada | Alta (7.5) | 4.6% | — | Oracle JRESUN Java WEB StartSUN Jsse | 31/12/2003 | 16/6/2026 | X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper… | |
| Modificada | Baja (2.1) | 0.39% | — | Astart Technologies Lprng | 5/5/2003 | 16/6/2026 | psbanner en el paquete LPRng permite a usuarios locales sobreescribir ficheros mediante un ataque de enlaces simbólicos en fichero /tmp/before | |
| Modificada | Media (5) | 8.1% | 💥 Exploit | Astaware SearchdiscSunone Starter KIT | 2/4/2003 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en ASTAware SearchDisk engine en Sun ONE Starter Kit 2.0 permite a atacantes remotos leer ficheros arbitrarios mediante un ataque de .. (punto punto)en los puertos 6015 ó 6016, o una ruta absoluta en el puerto 6017 | |
| Modificada | Alta (7.5) | 1.5% | — | Utstarcom BAS 1000 | 31/12/2002 | 16/6/2026 | UTStarcom BAS 1000 3.1.10 creates several default or back door accounts and passwords, which allows remote attackers to gain access via (1) field account with a password of "*field", (2) guru account with a password of "*3noguru", (3) snmp account with a password of "snmp", or (4) dbase account with a password of… | |
| Modificada | Baja (2.1) | 0.38% | — | Astaro Security Linux | 31/12/2002 | 16/6/2026 | Astaro Security Linux 2.016 creates world-writable files and directories, which allows local users to overwrite arbitrary files. | |
| Modificada | Alta (7.5) | 1.8% | — | SUN Java WEB Start | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors. | |
| Modificada | Alta (7.5) | 9.9% | — | ISC BindAstaro Security Linux | 29/11/2002 | 16/6/2026 | Desbordamientos de búfer en la libreria de resolución de raíz DNS en ISC BIND 4.9.2 a 4.9.10, y otras librerías derivadas como BSD libc y GNU libc, permite a atacantes remotos ejecutar código arbitrario mediante respuestas de servidor DNS que disparan el desbordamiento en las funciones getnetbyname() y getnetbyaddr().… | |
| Modificada | Media (4.6) | 0.80% | 💥 Exploit | EcartisListar | 12/8/2002 | 16/6/2026 | Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or… |