Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 11% | — | Apache Http Server | 29/3/2004 | 16/6/2026 | Fuga de meoria en ssl_engine_io.c en mod_ssl de Apache 2 anteriores a 2.0.49 permite a atacantes remotos causar una denegación de servicio (consumición de memoria) mediante peticiones HTTP regulares al puerto SSL de un servidor con SSL activado. | |
| Modificada | Baja (2.1) | 3.5% | — | Apache Http Server | 20/3/2004 | 16/6/2026 | mod_disk_cache in Apache 2.0 through 2.0.49 stores client headers, including authentication information, on the hard disk, which could allow local users to gain sensitive information. | |
| Modificada | Alta (7.5) | 5.6% | — | Apache Http Server | 3/3/2004 | 16/6/2026 | mod_digest de Apache no verifica adecuadamente el nonce de una respuesta de cliente usando un secreto AuthNonce. | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | An-http | 31/12/2003 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Apache Http Server | 31/12/2003 | 16/6/2026 | The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the server's process group and use the server's file descriptors, as demonstrated by sending a STOP signal, then intercepting incoming connections on the server's TCP port. NOTE: the PHP developer has… | |
| Modificada | Media (4.3) | 2.0% | — | Bajie Java Http Server | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message. | |
| Modificada | Media (6.4) | 4.0% | — | Http Fetcher Library | 31/12/2003 | 16/6/2026 | Buffer overflow in the http_fetch function of HTTP Fetcher 1.0.0 and 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request via a long (1) host, (2) referer, or (3) userAgent value. | |
| Modificada | Media (5) | 1.4% | — | An-http | 31/12/2003 | 16/6/2026 | AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability. | |
| Modificada | Media (4.3) | 6.6% | — | Apache Http Server | 31/12/2003 | 16/6/2026 | Apache HTTP Server 1.3.22 through 1.3.27 on OpenBSD allows remote attackers to obtain sensitive information via (1) the ETag header, which reveals the inode number, or (2) multipart MIME boundary, which reveals child process IDs (PID). | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Http Commander | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers to view arbitrary files via a .. (dot dot) in the file parameter. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Bajie Java Http Server | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet. | |
| Modificada | Media (5) | 2.1% | — | An-http | 31/12/2003 | 16/6/2026 | AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message. | |
| Modificada | Media (5) | 1.9% | — | Http CommanderAI | 31/12/2003 | 16/6/2026 | HTTP Commander 4.0 allows remote attackers to obtain sensitive information via an HTTP request that contains a . (dot) in the file parameter, which reveals the installation path in an error message. | |
| Modificada | Media (5) | 1.6% | — | Cherokee Httpd | 26/12/2003 | 16/6/2026 | connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field. | |
| Modificada | Alta (7.2) | 30% | — | Apache Http Server | 3/11/2003 | 16/6/2026 | Múltiples desbordamientos de búfer en mod_alias y mod_rewrite de Apache anteriores a 1.3.29, con consecuencias y métodos de ataque desconocidos, relacionados con una expresión regular con más de 9 capturas. | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Acme Thttpd | 3/11/2003 | 16/6/2026 | Desbordamiento de búfer en la función defang en libhttpd.c de thttpd 2.21 a 2.23b1, permite a atacantes remotos ejecutar código de su elección mediante peticiones que contienen caracteres '<' ó '>' que provocan el desbordamiento cuando son expandidos a las secuencias "<" y ">". | |
| Modificada | Alta (10) | 12% | — | Apache Http Server | 3/11/2003 | 16/6/2026 | mod_cgid en Apache anteriores a 2.0.48, cuando usan una MPM multihilo, no maneja adecuadamente redirecciones de ruta de CGI, lo que podría causar que Apache enviar la salida de un programa CGI a un cliente equivocado. | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | Charles Steinkuehler Sh-httpd | 27/10/2003 | 16/6/2026 | Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character. | |
| Modificada | Media (5) | 13% | — | Apache Http Server | 27/8/2003 | 16/6/2026 | El programa rotatelogs en Apache anteriores a 1.3.28 para Windows y OS/2, no ignora adecuadamente ciertos caractéres de control que son recibidos por la tubería, lo que podría permitir a atacantes remotos causar una denegación de servicio. | |
| Modificada | Media (5) | 9.2% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | Apache 2 anteriores a la 2.0.47, cuando es ejecutado en un sistema IPv6, permite a atacantes causar la Denegación de Servicios (DoS) cuando el servidor proxy FTP falla al crear una conexión IPv6. | |
| Modificada | Media (5) | 9.1% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | El MPM pre-desdoblamiento (prefork) en Apache 2 anteriores a 2.0.47 no maneja apropiadamente ciertos errores de accept(), lo que podría llevar a una denegación de servicio. | |
| Modificada | Media (6.4) | 6.0% | — | Apache Http Server | 18/8/2003 | 16/6/2026 | Apache 2 anteriores a 2.0.47, y ciertas versiones de mod_ssl para Apache 1.3, no manejan adecuadamente "ciertas secuencias de re-negociaciones por directorio junto con la directiva SSLCipherSuite siendo usada para mejorar de un nivel de cifrado (ciphersuite) débil a uno fuerte", lo que podría hacer que apache… | |
| Modificada | Media (5) | 63% | 💥 Exploit | Apache Http Server | 9/6/2003 | 16/6/2026 | Vulnerabilidad desconocida en Apache 2.0.37 hasta 2-0-45 permite que atacantes remotos provoquen una denegación de servicio (caída) mediante mod_dav y posiblemente otros vectores. | |
| Modificada | Media (5) | 15% | — | Apache Http Server | 9/6/2003 | 16/6/2026 | El módulo de autenticación para Apache 2.0.40 hasta 2.0.45 en Unix no maneja de manera segura los threads cuando usa las funciones crypt_r o crypt, lo que permite que atacantes remotos provoquen una denegación de servicio cuando se usa un thread MPM (autentificación básica fallida con nombres de usuarios y passwords… |