Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
938 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.36% | — | Broadcom Unicenter Asset Management | 2/3/2005 | 16/6/2026 | Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods. | |
| Modificada | Media (4.3) | 1.3% | — | Broadcom Unicenter Asset Management | 2/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 9/2/2005 | 16/6/2026 | Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file… | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus GatewayBroadcom Etrust EZ Antivirus+18 | 10/1/2005 | 16/6/2026 | El módulo Perl Archive::Zip anterior a 1.14, cuando se usa en programas antivirus como amavisd-new, permite a atacantes remotos saltarse la protección del antivirus mediante un ficheros comprimido con cabeceras globales y locales establecido a cero, lo que no impide que el fichero comprimido sea abierto en un sistema… | |
| Modificada | Alta (7.2) | 0.41% | — | Broadcom Etrust EZ Antivirus | 10/1/2005 | 16/6/2026 | Computer Associates eTrust EZ Antivirus 7.0.0 to 7.0.4, including 7.0.1.4, installs its files with insecure permissions (ACLs), which allows local users to gain privileges by replacing critical programs with malicious ones, as demonstrated using VetMsg.exe. | |
| Modificada | Alta (10) | 45% | — | Broadcom Unicenter TNG | 31/12/2004 | 16/6/2026 | Multiple stack-based buffer overflows in Agent Common Services (1) cam.exe and (2) awservices.exe in Unicenter TNG 2.4 allow remote attackers to execute arbitrary code. | |
| Modificada | Media (6.8) | 2.2% | — | Quadcomm Q-shop | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) imagezoom.asp or (2) recommend.asp in Q-Shop allow remote attackers to execute arbitrary script and steal the user session ID via Javascript in a URL. | |
| Modificada | Alta (7.5) | 3.2% | — | Quadcomm Q-shop | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in QuadComm Q-Shop allow remote attackers to execute arbitrary SQL commands via certain parameters to (1) search.asp, (2) browse.asp, (3) details.asp, (4) showcat.asp, (5) users.asp, (6) addtomylist.asp, (7) modline.asp, (8) cart.asp, or (9) newuser.asp. | |
| Modificada | Media (5) | 2.7% | — | Broadcom Etrust Antivirus EE | 31/12/2004 | 16/6/2026 | Computer Associates eTrust Antivirus EE 6.0 through 7.0 allows remote attackers to bypass virus scanning by including a password-protected file in a ZIP file, which causes eTrust to scan only the password protected file and skip the other files. | |
| Modificada | Baja (2.1) | 0.47% | — | Broadcom Common ServicesBroadcom Unicenter Network AND Systems ManagementBroadcom Unicenter Serviceplus Service Desk | 31/12/2004 | 16/6/2026 | Computer Associates Unicenter Common Services 3.0 and earlier stores the database "SA" password in cleartext in the TndAddNspTmp.bat file, which could allow local users to gain privileges. | |
| Modificada | Alta (7.5) | 0.86% | — | Broadcom Bluecoat Security Gateway | 31/12/2004 | 16/6/2026 | The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates. | |
| Modificada | Media (6.4) | 1.6% | — | Tridcomm | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in the FTP server in TriDComm 1.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in FTP commands such as (1) DIR, (2) GET, or (3) PUT. | |
| Modificada | Baja (2.1) | 0.46% | — | Broadcom Inoculateit | 23/11/2004 | 16/6/2026 | Los scripts (1) inorgupdate, (2) uniftest, o (3) unimove de eTrust InoculateIT 6.0 para Linux permiten a usuarios locales sobreescribir ficheros de su elección mediante un ataque de enlaces simbólicos en /tmp. | |
| Modificada | Alta (7.5) | 3.6% | — | Widcomm Bluetooth Communication SoftwareWidcomm Btstackserver | 20/10/2004 | 16/6/2026 | Desbordamiento de búfer en WIDCOMM Bluetooth Connectivity Software, usado en productos como BTStackServer 1.3.2.7 y 1.4.2.10, Windows XP y Windows 98 con mochilas Bluetooth MSI, y HP IPAQ 5450 con WinCE 3.0, permite a atacantes remotos ejecutar código de su elección mediante ciertas peticiones de servicio. | |
| Modificada | Media (5) | 4.2% | — | Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+2 | 4/9/2004 | 16/6/2026 | Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets. | |
| Modificada | Media (4.6) | 0.47% | — | Broadcom Inoculateit | 9/2/2004 | 16/6/2026 | eTrust InoculateIT for Linux 6.0 uses insecure permissions for multiple files and directories, including the application's registry and tmp directories, which allows local users to delete, modify, or examine sensitive information. | |
| Modificada | Media (4.6) | 0.38% | — | Broadcom Unicenter Remote Control Host | 5/1/2004 | 16/6/2026 | "Vulnerabilidad de seguridad de sistema" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes ganar privilegios mediante el interfaz de ayuda. | |
| Modificada | Media (4.6) | 0.37% | — | Broadcom Unicenter Remote ControlBroadcom Unicenter Remote Control OptionCA ControlitCA Unicenter Remote Control Option | 5/1/2004 | 16/6/2026 | "vulnerabilidad potencial de seguridad de sistema" desconocida en Computer Associates (CA) Unicenter Remote Control 5.0 a 5.2, y ControlIT 5.0 y 5.1 puede permitir a atacantes ganar privilegios de la cuenta de sistema local. | |
| Modificada | Media (5) | 1.3% | — | Broadcom Unicenter Remote Control Host | 5/1/2004 | 16/6/2026 | Vulnerabilidad de "ataque de denegación de servicio" desconocida en Computer Associates (CA) Unicenter Remote Control (URC) 6.0 permite a atacantes causar una denegación de servicio (consumición de CPU en anfitrión del servicio URC). | |
| Modificada | Media (4.3) | 2.1% | — | Broadcom Inoculateit | 31/12/2002 | 16/6/2026 | eTrust InoculateIT 6.0 with the "Incremental Scan" option enabled may certify that a file is free of viruses before the file has been completely downloaded, which allows remote attackers to bypass virus detection. |