Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.38% | — | Gemalto Safenet Authentication Service END User Software Tools FOR Windows | 2/3/2018 | 17/6/2026 | SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module. | |
| Modificada | Baja (1.3) | 0.43% | — | Gemalto Safenet Luna G5Gemalto Safenet Luna Pci-eGemalto Safenet Luna SA | 22/7/2015 | 17/6/2026 | The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition. | |
| Modificada | Alta (7.8) | 3.8% | — | Safenet-inc Safenet Authentication Service Outlook WEB Access Agent | 16/12/2014 | 17/6/2026 | Directory traversal vulnerability in SafeNet Authentication Service (SAS) Outlook Web Access Agent (formerly CRYPTOCard) before 1.03.30109 allows remote attackers to read arbitrary files via a .. (dot dot) in the GetFile parameter to owa/owa. | |
| Modificada | Media (5.4) | 0.27% | — | Safenet-inc Safenetmobile Pass | 11/9/2014 | 17/6/2026 | The SafeNetMobile Pass (aka securecomputing.devices.android.controller) application 8.3.7.11 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.3% | — | 7T IgssSafenet-inc Sentinel Hasp Run-timeSafenet-inc Sentinel Hasp SDK | 17/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin Control Center in Sentinel HASP Run-time Environment 5.95 and earlier in SafeNet Sentinel HASP (formerly Aladdin HASP SRM) run-time installer before 6.x and SDK before 5.11, as used in 7 Technologies (7T) IGSS 7 and other products, when Firefox 2.0 is used, allows… | |
| Modificada | Media (6.8) | 4.8% | — | Aladdin Safenet Securewire Access GatewayCisco Adaptive Security ApplianceSonicwall E-class SSL VPNSonicwall SSL VPN+1 | 4/12/2009 | 16/6/2026 | Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that… | |
| Modificada | Media (6.9) | 3.7% | 💥 Exploit | Safenet-inc Softremote | 4/11/2009 | 16/6/2026 | Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd). | |
| Modificada | Alta (10) | 72% | 💥 Exploit | Safenet-inc SoftremoteSafenet-inc Softremote1.4 | 5/6/2009 | 16/6/2026 | Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 13/2/2008 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483. | |
| Modificada | Alta (7.2) | 0.84% | 💥 Exploit | Safenet Ipsecdrv.sysSafenet Highassurance RemoteSafenet Softremote VPN Client | 5/2/2008 | 16/6/2026 | IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Safenet Sentinel Keys ServerSafenet Sentinel Protection Server | 20/12/2007 | 16/6/2026 | Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string. | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Safenet Highassurance RemoteSafenet Softremote VPN Client | 11/6/2007 | 16/6/2026 | IPSecDrv.sys 10.4.0.12 in SafeNET High Assurance Remote 1.4.0 Build 12, and SoftRemote, allows remote attackers to cause a denial of service (infinite loop and system hang) via an invalid packet with certain bytes in an option header, possibly related to the IPv6 support for IPSec. | |
| Modificada | Baja (2.1) | 0.39% | — | Syworks Safenet | 12/6/2006 | 16/6/2026 | Syworks SafeNET allows local users to bypass restrictions on network resource consumption by editing the policy.dat file. | |
| Modificada | Baja (2.1) | 0.44% | — | Safenet Softremote VPN Client | 2/5/2005 | 16/6/2026 | SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Safenet Sentinel License Manager | 2/5/2005 | 16/6/2026 | Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093. | |
| Modificada | Media (5.1) | 3.0% | — | Safenet Softremote VPN Client | 31/12/2002 | 16/6/2026 | SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflows using (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload. |