Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.8% | 💥 Exploit | Ispworker | 5/11/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ticketid and (2) filename parameters. | |
| Modificada | Alta (9.3) | 7.1% | — | EMC Legato Networker | 21/8/2007 | 16/6/2026 | Stack-based buffer overflow in the NetWorker Remote Exec Service (nsrexecd.exe) in EMC Software NetWorker 7.x.x allows remote attackers to execute arbitrary code via a (1) poll or (2) kill request with a "long invalid subcmd." | |
| Modificada | Alta (10) | 4.6% | — | EMC Networker | 2/3/2007 | 16/6/2026 | The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5) | 2.5% | — | EMC Legato Networker | 31/12/2005 | 16/6/2026 | nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to… | |
| Modificada | Alta (7.5) | 5.2% | — | EMC Legato Networker | 31/12/2005 | 16/6/2026 | Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of… | |
| Modificada | Alta (7.5) | 4.5% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 rely on AUTH_UNIX authentication, which relies on user ID for authentication and allows remote attackers to bypass authentication and gain privileges by spoofing a username or UID. | |
| Modificada | Media (6.4) | 4.3% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service by using pmap_unset to un-register a NetWorker service, or (2)… | |
| Modificada | Alta (7.5) | 4.6% | — | EMC Legato NetworkerSUN Solstice BackupSUN Storedge Enterprise Backup Software | 23/8/2005 | 16/6/2026 | EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token. | |
| Modificada | Alta (7.2) | 0.40% | — | Fujitsu Siemens Networker | 31/12/2003 | 16/6/2026 | nsr_shutdown in Fujitsu Siemens NetWorker 6.0 allows local users to overwrite arbitrary files via a symlink attack on the nsrsh[PID] temporary file. | |
| Modificada | Baja (3.6) | 0.29% | — | Ralf Hoffmann Worker Filemanager | 31/12/2003 | 16/6/2026 | Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information. | |
| Modificada | Media (4.6) | 0.37% | — | EMC Networker | 25/3/2002 | 16/6/2026 | EMC NetWorker (formerly Legato NetWorker) before 7.0 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform. | |
| Modificada | Media (4.6) | 0.37% | — | EMC Networker | 25/3/2002 | 16/6/2026 | EMC NetWorker (formerly Legato NetWorker) before 7.0 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges. NOTE: this was originally reported for Legato NetWorker 6.1 on the Solaris 7 platform. | |
| Modificada | Alta (7.5) | 2.4% | — | EMC Networker | 21/11/2001 | 16/6/2026 | Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup. |