Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.6% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Alta (7.8) | 4.1% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter. | |
| Modificada | Media (6.8) | 3.1% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System Identity Manager | 18/11/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System Messaging Server | 17/11/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904. | |
| Modificada | Alta (10) | 10% | — | SUN Java WEB Start | 4/11/2008 | 16/6/2026 | The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method. | |
| Modificada | Baja (2.1) | 0.39% | — | SUN Java Access Manager | 27/10/2008 | 16/6/2026 | Unspecified vulnerability in the search feature in Sun Java System LDAP JDK before 4.20 allows context-dependent attackers to obtain sensitive information via unknown attack vectors related to the LDAP JDK library. | |
| Modificada | Alta (10) | 8.4% | — | SUN Java System WEB Proxy Server | 13/10/2008 | 16/6/2026 | Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request. | |
| Modificada | Media (5) | 2.5% | — | SUN Java System WEB Proxy Server | 14/8/2008 | 16/6/2026 | Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors. | |
| Modificada | Alta (10) | 5.9% | — | SUN Java Platform Micro EditionSUN Wireless Toolkit | 8/8/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in Sun Java Platform Micro Edition (aka Java ME, J2ME, or mobile Java), as distributed in Sun Wireless Toolkit 2.5.2, allow remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable… | |
| Modificada | Alta (7.5) | 2.4% | — | SUN Java | 1/8/2008 | 16/6/2026 | Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Media (6.5) | 2.0% | — | SUN Java System WEB Server PluginSUN N1 Service Provisioning System | 31/7/2008 | 16/6/2026 | Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors. | |
| Modificada | Media (6.8) | 2.8% | — | Webkit Javascriptcore | 14/7/2008 | 16/6/2026 | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability… | |
| Modificada | Alta (7.5) | 2.8% | — | SUN Java System Access ManagerSUN Java System Identity Server | 30/6/2008 | 16/6/2026 | Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and… | |
| Modificada | Media (4.3) | 4.8% | — | Oracle Glassfish ServerSUN Java System Application Server | 18/6/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2)… | |
| Modificada | Alta (7.1) | 2.5% | — | SUN Java System Calendar ServerSUN ONE Calendar Server | 18/6/2008 | 16/6/2026 | Unspecified vulnerability in cshttpd in Sun Java System Calendar Server 6 and 6.3, and Sun ONE Calendar Server 6.0, when access logging (aka service.http.commandlog.all) is enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors. | |
| Modificada | Alta (9.3) | 3.6% | — | SUN Java System Access Manager | 16/6/2008 | 16/6/2026 | Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Media (5) | 11% | — | SUN Java ASP Server | 4/6/2008 | 16/6/2026 | The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents. | |
| Modificada | Alta (10) | 19% | — | SUN Java ASP Server | 4/6/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method. | |
| Modificada | Alta (10) | 6.6% | — | SUN Java ASP Server | 4/6/2008 | 16/6/2026 | Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field. | |
| Modificada | Alta (7.5) | 3.3% | — | SUN Java ASP Server | 4/6/2008 | 16/6/2026 | The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102. | |
| Modificada | Alta (7.5) | 3.2% | — | SUN Java Active Server Pages | 4/6/2008 | 16/6/2026 | Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications. | |
| Modificada | Alta (7.5) | 2.5% | — | SUN Java Active Server | 4/6/2008 | 16/6/2026 | The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System WEB Server | 3/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the next parameter. | |
| Modificada | Media (4.3) | 1.9% | — | SUN Java System WEB Server | 13/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp. |