Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
–

1212 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.3%—Gnome Dwarf Http Server13/3/200616/6/2026
Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request.
ModificadaMedia (4.3)1.4%—Gnome Dwarf Http Server13/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages.
ModificadaAlta (8.4)0.54%—Acme Labs Thttpd9/3/200616/6/2026
Múltiples desbordamientos de búfer en htpasswd, como se utiliza en Acme thttpd 2.25b y posiblemente otros productos tales como Apache, podrían permitir a usuarios locales obtener privilegios a través de (1) un argumento de línea de comando largo y (2) una línea larga en un archivo. NOTA: debido a que htpasswd…
ModificadaAlta (7.2)0.40%—Acme Labs Thttpd9/3/200616/6/2026
htpasswd, como se utiliza en Acme thttpd 2.25b y posiblemente otros productos tales como Apache, podrían permitir a usuarios locales obtener privilegios a través de metacaracteres de shell en un argumento de línea de comando, lo que se utiliza en una llamada a la función del sistema. NOTA: debido a que htpasswd…
ModificadaMedia (5)1.5%—Raidenhttpd6/3/200616/6/2026
RaidenHTTPD 1.1.47 permite a atacantes remotos obtener el código fuente de ficheros de guiones, incuyendo PHP, mediante peticiones artesanales conllevando caracteres (1) "." (punto), (2) espacio, y (3) "/" (barra).
ModificadaMedia (5)11%—Lighttpd6/3/200616/6/2026
response.c en Lighttpd 1.4.10 y posiblemente versiones anteriores, cuando se ejecuta sobre Windows, permite a atacantes leer código fuente de su elección mediante peticiones conteniendo caractéres (1) "." (punto) y (2) espacio al final, que son ignoradas por Windows, como se ha demostrado en ficheros PHP.
ModificadaBaja (2.6)2.2%—Lighttpd18/2/200616/6/2026
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for…
ModificadaAlta (7.5)6.8%—Oracle Application ServerOracle Http Server26/1/200616/6/2026
Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the…
ModificadaAlta (10)13%—HP Http Server31/12/200516/6/2026
Buffer overflow in the HP HTTP Server 5.0 through 5.95 of the HP Web-enabled Management Software allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5.4)24%—Apache Http Server31/12/200516/6/2026
mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.
ModificadaMedia (4.3)2.5%💥 ExploitNet-square Httprint22/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in httprint v202, and possibly other versions before v301, allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response, which is not sanitized before being displayed to the user.
ModificadaMedia (5)4.5%💥 ExploitNet-square Httprint22/12/200516/6/2026
httprint v202, and possibly other versions before v301, allows remote attackers to cause a denial of service (crash) via a long Server field in an HTTP response.
ModificadaMedia (4.3)74%—Apache Http Server13/12/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el módulo mod_imap de Apache httpd anteriores a 1.3.35-dev y Apache httpd 2.0.x anteriores a 2.0.56-dev permite a atacantes remotos inyectar 'script' web o HTML de su elección mediante el Referente cuando se usan mapas de imágenes.
ModificadaBaja (2.1)0.37%—Acme Labs Thttpd6/11/200516/6/2026
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (5)14%—Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+225/10/200516/6/2026
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
ModificadaMedia (4.3)0.97%—Compaqhttpserver20/9/200516/6/2026
Cross-site scripting (XSS) vulnerability in CompaqHTTPServer 2.1 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page.
ModificadaAlta (10)31%—Apache Http ServerDebian LinuxCanonical Ubuntu Linux6/9/200516/6/2026
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
ModificadaMedia (5)11%—Apache Http Server30/8/200516/6/2026
The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.
ModificadaMedia (5)8.4%—Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+15/8/200516/6/2026
Error de fuera-por-uno en la retrollamda de verificación de Lista de Revocación de Certificados (CRL) de mod_ssl para Apache, cuando se configura para usar un CRL, permite a atacantes remotos causar una denegación de servicio (caída de proceso hijo) mediante una CRL que causa un desbordamiento de búfer de un byte nule.
ModificadaMedia (4.3)20%—Apache Http ServerDebian Linux5/7/200516/6/2026
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes…
ModificadaAlta (7.5)10.0%💥 ExploitOrenosv Http FTP Server18/5/200516/6/2026
Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3)…
ModificadaMedia (6.4)5.6%💥 ExploitAn-httpd2/5/200516/6/2026
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.
ModificadaMedia (5)1.8%—Sami Http Server2/5/200516/6/2026
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
ModificadaAlta (7.5)29%💥 ExploitApache Http Server2/5/200516/6/2026
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI…
ModificadaMedia (5)3.1%—Sami Http Server2/5/200516/6/2026
Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.
Orbitaley — Vulnerabilidades