Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2713▼ 170 respecto a la semana anterior
Críticas / altas1244▼ 301 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 186 respecto a la semana anterior
883 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.0% | — | Electronic Arts Nascar Racing | 6/7/2006 | 16/6/2026 | Papyrus NASCAR Racing v4 4.1.3.1.6 y anteriores, 2002 Season v1.1.0.2 y anteriores y 2003 Season v1.2.0.1 y anteriores; permite a atacantes remotos provocar una denegación de servicio (consumo de la CPU) enviando un datagrama UDP vacío, el cuál no es descartado adecuadamente debido al uso del socket asíncrono FIONREAD. | |
| Modificada | Baja (2.6) | 1.4% | 💥 Exploit | Patronet CMS | 13/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Kryptronic Clickcartpro | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter. | |
| Modificada | Media (5) | 1.2% | — | Lantronix Securelinx | 11/7/2005 | 16/6/2026 | Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys. | |
| Modificada | Media (5) | 1.7% | — | Firefly Studios Stronghold 2 | 30/5/2005 | 16/6/2026 | Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception. | |
| Modificada | Media (5) | 1.6% | — | LG Electronics LG Mobile Phone | 2/5/2005 | 16/6/2026 | LG U8120 mobile phone allows remote attackers to cause a denial of service (device crash) via a malformed MIDI file. | |
| Modificada | Media (5.3) | 3.5% | 💥 Exploit | Armagetronad ArmagetronArmagetronad Armagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array. | |
| Modificada | Media (5) | 1.3% | — | ArmagetronArmagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | ArmagetronArmagetron Advanced | 2/5/2005 | 16/6/2026 | Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket. | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Conceptronic Cadslr1 Adsl Router | 31/12/2004 | 16/6/2026 | The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to cause a denial of service (device reboot) via an HTTP request with a long username. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Monolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron | 31/12/2004 | 16/6/2026 | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that… | |
| Modificada | Media (5.1) | 4.3% | 💥 Exploit | Electronic Arts Need FOR Speed HOT Pursuit 2 | 31/12/2004 | 16/6/2026 | Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands. | |
| Modificada | Alta (10) | 2.8% | — | Frees WANSuper Frees WANOpenswanStrongswan | 6/12/2004 | 16/6/2026 | FreeS/WAN 1.x y 2.x, y otros productos relacionados, incluyendo superfreeswan 1.x, openswan 1.x anteriores a 1.0.6, openswan 2.x anteriores a 2.1.4 y strongSwan anteriores a 2.1.3 permite a atacantes remotos autenticarse usando certificados PKCS#7 falsificados en los que un certificado auto-firmado identifica a una… | |
| Modificada | Alta (7.5) | 62% | 💥 Exploit | Electronic Arts Medal OF Honor Allied Assault | 27/7/2004 | 16/6/2026 | Desbordamiento de búfer en Medal of Honor (1) Allied Assault 1.11v9 y anteriores, (2) Breakthrough 2.40b y anteriores, and (3) Spearhead 2.15 y anteriores, cuando se juega en una red de área local, permite a atacantes remotos ejecutar código arbitrario mediante vectores como (1) la consulta getinfo, (2), el paquete… | |
| Modificada | Alta (7.5) | 2.8% | — | Proxomitron Naoko | 31/12/2003 | 16/6/2026 | Buffer overflow in Proxomitron Naoko 4.4 allows remote attackers to execute arbitrary code via a long request. | |
| Modificada | Alta (7.5) | 4.5% | 💥 Exploit | Electronic Arts Battlefield 1942 | 31/12/2003 | 16/6/2026 | Buffer overflow in the remote console (rcon) in Battlefield 1942 1.2 and 1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long user name and password. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Nokia Electronic Documentation | 6/10/2003 | 16/6/2026 | Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos usar NED como un proxy HTTP abierto mediante una URL en el parámetro de localización, al que NED accede y devuelve al usuario. | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | Nokia Electronic Documentation | 6/10/2003 | 16/6/2026 | Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos obtener un listado de directorio de la raíz del web de WebLogic, y la ruta física del servidor NED, mediante una acción "retrieve" (obtener) con un parámetro de localización de . (dot). | |
| Modificada | Media (4.3) | 12% | 💥 Exploit | Nokia Electronic Documentation | 6/10/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Nokia Electronics Documentation (NED) 5.0 permite a atacantes remotos ejecutar script web arbitrario y robar galletitas (cookies) mediante una URL al directorio docs/ que contenga el script. | |
| Modificada | Alta (10) | 5.9% | 💥 Exploit | Cyberstrong Eshop | 7/8/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Cyberstrong eShop 4.2 y anteriores permite a atacantes remotos robar información de autenticación y ganar privilegios mediante el parámetro ProductCode en (1) 10expand.asp, (2) 10browse.asp, y (3) 20review.asp. | |
| Modificada | Alta (7.5) | 4.2% | — | Cistron Radius Daemon | 7/8/2003 | 16/6/2026 | El demonio RADIUS Cistron (radiusd-cistron) 1.6.6 y anteriores permite a atacantes remotos causar una dengación de servicio y posiblemente ejecutar código arbitrario mediante un valor largo en el atributo NAS-Port, que es interpretado como un número negativo y causa un desbordamiento de búfer. | |
| Modificada | Media (5) | 1.3% | — | Kryptronic Clickcartpro | 31/12/2002 | 16/6/2026 | ClickCartPro 4.0 stores the admin_user.db data file under the web document root with insufficient access control on servers other than Apache, which allows remote attackers to obtain usernames and passwords. | |
| Modificada | Alta (7.5) | 8.5% | — | Ascend RadiusFreeradiusGNU RadiusIcradius+8 | 4/3/2002 | 16/6/2026 | Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data. | |
| Modificada | Media (5) | 5.4% | — | FreeradiusGNU RadiusIcradiusLivingston Radius+7 | 4/3/2002 | 16/6/2026 | Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. |