Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2782▼ 316 respecto a la semana anterior
Críticas / altas1289▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
921 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 41% | 💥 Exploit | Honeywell Ademco Atnbaseloader100 ModuleMicrosoft Internet Explorer | 31/5/2007 | 16/6/2026 | Desbordamiento de búfer en el controlado ActiveX BaseRunner en el módulo Ademco ATNBaseLoader100 (ATNBaseLoader100.dll) 5.4.0.6, cuando se está utilizando Internet Explorer 6, permite a atacantes remotos ejecutar código de su elección a través de argumentos largos en los métodos (1) Send485CMD , y posiblemente el (2)… | |
| Modificada | Alta (9) | 1.5% | — | EMC RSA Security Sitekey | 30/4/2007 | 16/6/2026 | EMC RSA Security SiteKey emite vales de exención de desafío (challenge-bypass tokens) que persisten para siempre sin una interfaz de cancelación para los usuarios finales, lo cual facilita a los atacantes evitar una fase de la autenticación mediante el robo y reproducción de un vale. | |
| Modificada | Alta (8.5) | 2.3% | — | EMC RSA Security Sitekey | 30/4/2007 | 16/6/2026 | EMC RSA Security SiteKey permite a atacantes remotos mostrar la imagen correcta mediante un ataque de hombre-en-medio (MITM) en el cual un servidor controlado por el atacante hace de proxy para los datos de autenticación desde y hacia un servidor SiteKey legítimo. NOTA: el fabricante niega la severidad de este… | |
| Modificada | Alta (9.3) | 2.3% | — | EMC RSA Security Sitekey | 30/4/2007 | 16/6/2026 | EMC RSA Security SiteKey no establece el cualificador de seguridad en el testigo (token) SiteKey Flash (también conocido como el objeto compartido PassMark Flash), el cual permite a atacantes remotos obtener el testigo vía HTTP. | |
| Modificada | Alta (10) | 4.6% | — | EMC Networker | 2/3/2007 | 16/6/2026 | El servidor de la consola de administración del EMC NetWorker (antiguamente el Legato NetWorker) 7.3.2 anterior a la actualización 1 del Jumbo, utiliza una autenticación débil, lo que permite a atacantes remotos ejecutar comandos de su elección. | |
| Modificada | Alta (7.5) | 8.1% | — | EMC Retrospect Client | 16/5/2006 | 16/6/2026 | Buffer overflow in EMC Retrospect Client 5.1 through 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet to port 497. | |
| Modificada | Alta (7.2) | 0.39% | — | EMC Retrospect | 3/5/2006 | 16/6/2026 | EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 does not drop privileges before opening files, which allows local users to execute arbitrary code via the File>Open dialog. | |
| Modificada | Media (4.6) | 0.38% | — | EMC Retrospect | 3/5/2006 | 16/6/2026 | EMC Retrospect for Windows 6.5 before 6.5.382, 7.0 before 7.0.344, and 7.5 before 7.5.1.105 allows local users to execute arbitrary code by replacing the Retrospect.exe file, possibly due to improper file permissions. | |
| Modificada | Media (5) | 1.8% | — | EMC Dantz Retrospect | 3/3/2006 | 16/6/2026 | EMC Dantz Retrospect 7 backup client 7.0.107, and other versions before 7.0.109, and 6.5 before 6.5.138 allows remote attackers to cause a denial of service (client termination and loss of backup service) via a malformed packet to TCP port 497, which triggers an assert error. | |
| Modificada | Alta (7.5) | 5.2% | — | EMC Legato Networker | 31/12/2005 | 16/6/2026 | Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of… | |
| Modificada | Media (5) | 2.5% | — | EMC Legato Networker | 31/12/2005 | 16/6/2026 | nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to… | |
| Modificada | Alta (7.5) | 4.6% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token. | |
| Modificada | Media (6.4) | 4.3% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2)… | |
| Modificada | Alta (7.5) | 4.5% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | EMC Navisphere Manager | 16/8/2005 | 16/6/2026 | Directory traversal vulnerability in EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (5) | 1.6% | — | EMC Navisphere Manager | 16/8/2005 | 16/6/2026 | EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot). | |
| Modificada | Alta (7.5) | 1.4% | — | EMC Eroom | 11/7/2005 | 16/6/2026 | eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks. | |
| Modificada | Alta (7.5) | 1.9% | — | EMC Eroom | 11/7/2005 | 16/6/2026 | eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file. | |
| Modificada | Media (4.6) | 0.37% | — | EMC Networker | 25/3/2002 | 16/6/2026 | Legato NetWorker 6.1 almacena passwords en texto plano en el fichero daemon.log que permite a usuarios locales tomar privilegios leyendo las passwords del fichero. | |
| Modificada | Media (4.6) | 0.37% | — | EMC Networker | 25/3/2002 | 16/6/2026 | Legato Networker 6.1 almacena ficheros de registro en el directorio /nsr/logs/ con permisos de lectura para todos los usuarios, lo que permite a usuarios locales leer información sensible y posiblemente ganar privilegios. | |
| Modificada | Alta (7.5) | 2.4% | — | EMC Networker | 21/11/2001 | 16/6/2026 | Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup. |