Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
891 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.1% | — | Cisco Transport ControllerCisco Optical Networking Systems SoftwareCisco ONS 15310-cl SeriesCisco ONS 15600+1 | 7/4/2006 | 16/6/2026 | The installation of Cisco Transport Controller (CTC) for Cisco Optical Networking System (ONS) 15000 series nodes adds a Java policy file entry with a wildcard that grants the java.security.AllPermission permission to any http URL containing "fs/LAUNCHER.jar", which allows remote attackers to execute arbitrary code on… | |
| Modificada | Alta (7.8) | 3.2% | — | Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3030 Concentator | 31/1/2006 | 16/6/2026 | Cisco VPN 3000 series concentrators running software 4.7.0 through 4.7.2.A allow remote attackers to cause a denial of service (device reload or user disconnect) via a crafted HTTP packet. | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Alta (7.8) | 2.1% | — | Cisco CatalystCisco Catalyst 1200 SeriesCisco Catalyst 1900 SeriesCisco Catalyst 2800 Series+67 | 15/12/2005 | 16/6/2026 | Conmutadores Cisco Catalyst no especificados permiten a atacantes remotos causar una denegación de servicio (caída de dispositivo) mediante un paquete IP con IPs y puertos de origen y destino iguales y con la bandera SYN. (tcc LanD). NOTA: La proveniencia de esta cuestión es desconocida; los detalles son obtenidos… | |
| Modificada | Alta (7.5) | 3.8% | — | Symantec Enterprise FirewallSymantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Gateway Security 300+6 | 23/11/2005 | 16/6/2026 | Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as… | |
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Neoteris Instant Virtual ExtranetJuniper Netscreen ScreenosNetscreen Ns-10Netscreen Ns-100+12 | 23/8/2005 | 16/6/2026 | Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates a response if the username is valid but does not respond when… | |
| Modificada | Media (5) | 2.3% | — | Cisco VPN 3000 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+4 | 20/6/2005 | 16/6/2026 | Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response for an invalid groupname. | |
| Modificada | Media (5) | 2.3% | — | IBM Iseries AS 400 | 2/5/2005 | 16/6/2026 | The FTP server in AS/400 4.3, when running in IFS mode, allows remote attackers to obtain sensitive information via a symlink attack using RCMD and the ADDLNK utility, as demonstrated using the QSYS.LIB library. | |
| Modificada | Media (5) | 1.7% | — | IBM Iseries AS 400 | 2/5/2005 | 16/6/2026 | The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server. | |
| Modificada | Alta (7.5) | 1.8% | — | IBM Iseries AS 400 | 2/5/2005 | 16/6/2026 | By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request. | |
| Modificada | Media (4.6) | 1.4% | — | Bottomline Webseries Payment Application | 2/5/2005 | 16/6/2026 | Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs. | |
| Modificada | Media (5) | 1.6% | — | Cisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 Concentrator+4 | 30/3/2005 | 16/6/2026 | Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Nokia Series | 6/3/2005 | 16/6/2026 | Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname. | |
| Modificada | Baja (3.6) | 0.69% | — | Bottomline Webseries Payment Application | 11/1/2005 | 16/6/2026 | The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords. | |
| Modificada | Media (5) | 1.4% | — | Bottomline Webseries Payment Application | 10/1/2005 | 16/6/2026 | Bottomline Webseries Payment Application allows remote attackers to read arbitrary files on the network via a report template with modified ReportPath or ReportName values. | |
| Modificada | Alta (7.5) | 9.5% | — | Hp-uxHp-ux Series 700Hp-ux Series 800HP SIS+1 | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in the FTP daemon in HP-UX 11.11i, with the -v (debug) option enabled, allows remote attackers to execute arbitrary code via a long command request. | |
| Modificada | Media (6) | 2.1% | — | Netscreen-sa 5000 Series | 23/11/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in delhomepage.cgi in NetScreen-SA 5000 Series running firmware 3.3 Patch 1 (build 4797) allows remote authenticated users to execute arbitrary script as other users via the row parameter. | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/4/2004 | 16/6/2026 | Múltiples desbordamientos de búfer basado en la pila en las rutinas de análisis de ICQ en el componente ISS Protocol Analysis Module (PAM), utilizado en varios productos RealSecure, Proventia y BlackICE, permite a atacantes remotos ejecutar código arbitrario mediante un respuesta SRV_MULTI conteniendo un paquete de… | |
| Modificada | Alta (7.5) | 8.0% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+7 | 15/3/2004 | 16/6/2026 | Desbordamiento de búfer basado en la pila en el Módulo de análisis de Protocolos (PAM) de ISS, usado en ciertas versiones de RealSecure Network 7.0 y Server Sensor 7.0, Proventia series A, G, y M, Desktop 7.0 y 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, y BlackICE Server Protection… | |
| Modificada | Media (5) | 2.1% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+2 | 27/5/2003 | 16/6/2026 | Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 3.6.7A permiten que atacantes remotos causen una denegación de servicio (ralentización y posiblemente recarga) mediante una inundación con paquetes ICMP mal construídos. | |
| Modificada | Alta (7.5) | 2.2% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+3 | 27/5/2003 | 16/6/2026 | Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 4.0.REL, cuando se configuran para permitir IPSec sobre TCP para un puerto del concentrador, permiten que atacantes remotos alcancen la red privada sin autentificación. | |
| Modificada | Media (5) | 2.1% | — | Cisco VPN 3015 ConcentratorCisco VPN 3030 ConcentatorCisco VPN 3060 ConcentratorCisco VPN 3080 Concentrator+2 | 27/5/2003 | 16/6/2026 | Concentradores de Cisco de la serie VPN 3000 y Cisco VPN 3002 Hardware Client 2.x.x hasta 3.6.7 permiten que atacantes remotos causen una denegación de servicio (recarga) mediante un paquete de inicialización SSH mal construído. | |
| Modificada | Alta (10) | 39% | 💥 Exploit | SendmailSendmail SwitchCompaq Tru64Hp-ux+5 | 2/4/2003 | 16/6/2026 | The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial… | |
| Modificada | Alta (7.5) | 15% | — | GNU GlibcMIT Kerberos 5OpenafsSGI Irix+9 | 25/3/2003 | 16/6/2026 | Desbordamiento de entero en la función xdrmem_getbytes(), y posiblemente otras funciones, de librerias XDR (representación de datos externos) derivadas de SunRPC, incluyendo libnsl, libc y glibc permite a atacantes remotos ejecutar código arbitrario mediante ciertos valores enteros en campos de longitud. |