Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.38% | — | SUN Java Studio Enterprise | 19/4/2006 | 16/6/2026 | Sun Java Studio Enterprise 8, when installed as root, creates certain files with world-writable permissions, which allows local users to execute arbitrary commands via unspecified vectors. | |
| Modificada | Media (5) | 9.9% | 💥 Exploit | SUN Java System Directory Server | 13/2/2006 | 16/6/2026 | LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attackers to cause a denial of service (memory allocation error) via an LDAP packet with a crafted subtree search request, as demonstrated using the ProtoVer LDAP test suite. | |
| Modificada | Alta (7.2) | 0.40% | — | SUN Java System Access Manager | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool. | |
| Modificada | Media (5) | 2.5% | — | SUN Java System WEB Proxy Server | 31/12/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors. | |
| Modificada | Media (5) | 1.7% | — | SUN Java Plug-in | 31/12/2005 | 16/6/2026 | The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | |
| Modificada | Media (5) | 2.2% | — | SUN Java System Application Server | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allows remote attackers to obtain the source code for Java Server pages (JSP) via unknown vectors. | |
| Modificada | Alta (10) | 2.5% | — | SUN Java | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in Java 1.3.1 before 1.3.1_16 on Apple Mac OS X allows an untrusted applet to gain privileges, related to "Mac OS X specific extensions." | |
| Modificada | Media (5) | 2.2% | — | Jboss Enterprise Java BeansAI | 31/12/2005 | 16/6/2026 | The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous… | |
| Modificada | Media (5) | 1.2% | — | SUN Javamail | 31/12/2005 | 16/6/2026 | ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments via a direct request to /mailboxesdir/username@domainname. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that… | |
| Modificada | Baja (1.2) | 0.32% | — | SUN Java | 31/12/2005 | 16/6/2026 | Race condition in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to corrupt files or create arbitrary files via unspecified attack vectors related to a temporary directory, possibly due to a symlink attack. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Apache TomcatSUN Javamail | 31/12/2005 | 16/6/2026 | JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to read arbitrary files via a full pathname in the argument to the Download parameter. NOTE: Sun and Apache dispute this issue. Sun states: "The report makes references to source code and files that do not exist in the mentioned… | |
| Modificada | Media (5) | 2.4% | — | SUN Java System Application Server | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications. | |
| Modificada | Media (5) | 1.8% | — | SUN Java | 31/12/2005 | 16/6/2026 | Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X does not prevent multiple programs from opening the same port as a Java ServerSocket, which allows local users to operate a Java program that intercepts network data intended for the ServerSocket of a different Java program. | |
| Modificada | Alta (10) | 2.3% | — | SUN Java | 31/12/2005 | 16/6/2026 | Unspecified vulnerability in Java 1.4.2 before 1.4.2 Release 2 on Apple Mac OS X allows local users to gain privileges via unspecified attack vectors relating to "the utility used to update Java shared archives." | |
| Modificada | Media (4) | 1.7% | — | SUN Java System Application ServerSUN ONE Application Server | 7/12/2005 | 16/6/2026 | Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, allows remote attackers to conduct man-in-the-middle (MITM)… | |
| Modificada | Alta (7.5) | 2.6% | — | SUN Java Communications Services Delegated Administrator | 7/12/2005 | 16/6/2026 | Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif. | |
| Modificada | Media (4.3) | 4.2% | 💥 Exploit | Java Search Engine | 3/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.jsp in Java Search Engine (JSE) 0.9.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | |
| Modificada | Media (5) | 2.3% | — | SUN Java System Communications Express | 3/11/2005 | 16/6/2026 | Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files. | |
| Modificada | Alta (7.5) | 3.1% | — | SUN Java System Directory Proxy ServerSUN Java System Directory ServerSUN ONE Administration ServerSUN ONE Directory Server | 20/10/2005 | 16/6/2026 | Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2… | |
| Modificada | Baja (2.1) | 0.40% | — | Linecontrol Java Client | 20/9/2005 | 16/6/2026 | AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files. | |
| Modificada | Media (5) | 0.99% | — | SUN Java System WEB Server | 7/6/2005 | 16/6/2026 | Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files. | |
| Modificada | Media (5) | 5.8% | 💥 Exploit | SUN Javamail | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header. | |
| Modificada | Alta (7.5) | 3.4% | — | SUN Java System WEB Proxy Server | 2/5/2005 | 16/6/2026 | Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 1.8% | — | SUN Java System WEB Server | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang). | |
| Modificada | Media (4.3) | 1.8% | — | SUN Java System Application Server | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. |