Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▼ 305 respecto a la semana anterior
Críticas / altas1294▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
–

943 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.4%—SUN Java System WEB Proxy Server2/5/200516/6/2026
Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5)2.5%—Initial Redirect Squid Proxy Plug-in2/5/200516/6/2026
Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.
ModificadaMedia (5)2.3%—Igor Khasilev Oops Proxy ServerGentoo Linux2/5/200516/6/2026
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
ModificadaAlta (7.5)1.1%—Christian Hilgers Http Anti Virus Proxy (havp)4/3/200516/6/2026
Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.
ModificadaAlta (10)4.3%—Proxytunnel1/3/200516/6/2026
Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.
ModificadaMedia (6.4)2.1%—Imap Proxy1/3/200516/6/2026
Multiple integer signedness errors in (1) imapcommon.c, (2) main.c, (3) request.c, and (4) select.c for up-imapproxy IMAP proxy 1.2.2 allow remote attackers to cause a denial of service (server crash) and possibly leak sensitive information via certain literal values that are not properly handled when using the…
ModificadaAlta (7.5)17%—Microsoft ISA ServerMicrosoft Proxy ServerMicrosoft Windows 2003 Server27/1/200516/6/2026
Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.
ModificadaMedia (5)2.1%—National Science Foundation Squid WEB Proxy Cache31/12/200416/6/2026
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
ModificadaMedia (4.3)1.9%—Phproxy31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHProxy allows remote attackers to inject arbitrary web script or HTML via the error parameter.
ModificadaMedia (4.6)2.1%—Myproxy31/12/200416/6/2026
MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.
ModificadaBaja (2.1)0.34%—Proxytunnel31/12/200416/6/2026
Unspecified vulnerability in cmdline.c in proxytunnel 1.1.3 and earlier allows local users to obtain proxy credentials (username or password) of other users.
ModificadaAlta (7.5)11%💥 ExploitYoungzsoft Ccproxy31/12/200416/6/2026
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.
ModificadaMedia (5)3.0%💥 ExploitNational Science Foundation Squid WEB Proxy Cache31/12/200416/6/2026
Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.
ModificadaAlta (10)7.6%💥 ExploitInternetnow Proxynow31/12/200416/6/2026
Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary code via a GET request with a long ftp:// URL.
ModificadaAlta (7.5)61%💥 ExploitYoungzsoft Ccproxy31/12/200416/6/2026
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)2.7%—Smtp.proxy31/12/200416/6/2026
Format string vulnerability in smtp.c for smtp.proxy 1.1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the (1) client hostname or (2) message-id, which are injected into a syslog message.
ModificadaMedia (5)10%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6123/11/200416/6/2026
El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio.
ModificadaAlta (7.5)9.5%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo.
ModificadaAlta (10)63%💥 ExploitProxy-pro Professional Gatekeeper23/11/200416/6/2026
Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaMedia (5)7.2%—Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+6223/11/200416/6/2026
OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS.
ModificadaAlta (10)64%💥 ExploitPsoproxy Server23/11/200416/6/2026
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.
ModificadaAlta (7.5)7.7%—SUN Java System WEB Proxy Server30/10/200416/6/2026
Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.
ModificadaAlta (10)71%💥 ExploitNational Science Foundation Squid WEB Proxy Cache6/8/200416/6/2026
Desbordamiento de búfer en la función ntlm_check_auth (autenticación NTLM) de Squid Web Proxy Cache 2.5.x y 3.x, cuando se compila con manejadores NTLM activados, permite a atacantes remotos ejecutar código de su elección mediante una contraseña larga (variable "pass")
ModificadaMedia (5)1.6%—IBM Websphere Caching Proxy ServerIBM Websphere Edge Server Caching Proxy6/8/200416/6/2026
WebSphere Edge Component Caching Proxy en WebSphere Edge Server 5.02con la directiva JunctionRewrite activada, permite a atacantes remotos causar una denegación de servicio mediante una petición HTTP GET sin parámetros.
ModificadaAlta (10)34%—Apache Http ServerHP VirtualvaultHP WebproxyIBM Http Server+36/8/200416/6/2026
Desbordamiento de búfer basado en el montón en proxy_util.c de mod_proxy en Apache 1.3.25 a 1.3.31 permite a atacantes remotos causar un denegación de servicio (caída del proceso) y posiblemente ejecutar código de su elección mediante un campo de cabecera HTTP Content-Length negativo, lo que causa que una gran…