Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2808▼ 273 respecto a la semana anterior
Críticas / altas1313▼ 193 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Omnicron Omnihttpd | 9/6/2003 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados en OmniHTTPd permiten que atacantes remotos inserten script o HTML en páginas web mediante: (1) test.php, (2) test.shtml o (3) redir.exe | |
| Modificada | Media (5) | 2.8% | — | Acme Labs Thttpd | 12/5/2003 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en thttpd, cuando se usan servidores virtuales, permite a atacantes remotos leer ficheros mediante secuencias .. (punto punto) en la cabecera Host: | |
| Modificada | Media (5) | 87% | 💥 Exploit | Apache Http Server | 11/4/2003 | 16/6/2026 | Vulnerabilidad desconocida en Apache de la 2.0 a la 2.0.44 permite a atacantes remotos causar una Denegación de Servicios significativa. | |
| Modificada | Media (5) | 6.0% | — | Apache Http Server | 11/4/2003 | 16/6/2026 | Vulnerabilidad desconocida en filestat.c de Apache bajo OS2, en versiones de la 2.0 a la 2.0.45, permite a atacantes desconocidos causar la Denegación de Servicios, posiblemente relacionada con un error en la identificación de ficheros no válidos. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Nulllogic Null Httpd | 2/4/2003 | 16/6/2026 | Vulnerabilidad de scripts en sitios cruzados (XSS) en Null HTTP Server 0.5.0 y anteriores permite a atacantes remotos insertar HTML arbitrario en una respuesta "404 No Encontrado". | |
| Modificada | Media (5) | 17% | — | Apache Http Server | 2/4/2003 | 16/6/2026 | Apache 1.3 anteriores a 1.3.25 y Apache 2.0 anteriores a 2.0.43 y posiblemente posteriores no filtran secuencias de escape de terminal de sus logs de acceso, lo que podría hacer más fácil para atacantes insertar esas secuencias secuencias en emuladores de terminal conteniendo vulnerabilidades relacionadas con… | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Nulllogic Null Httpd | 2/4/2003 | 16/6/2026 | Desbordamiento de búfer basado en el montón (heap) en Null HTTP Server 0.5.0 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante un valor negativo en la cabecera HTTP Content-Length. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Light Httpd | 31/3/2003 | 16/6/2026 | Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 16% | — | Apache Http Server | 18/3/2003 | 16/6/2026 | Apache no filtra secuencias de escape de terminales en sus archivos de registro de errores, lo que podría hacer más fácil para atacantes insertar estas secuencias en emuladores de terminal que tengan vulnerabilidades relacionadas con secuencias de escape. | |
| Modificada | Media (5) | 6.4% | — | Apache Http Server | 7/2/2003 | 16/6/2026 | Apache 2.0 anterior a 2.0.44 en plataformas Windows permite a atacantes remotos obtener determinados ficheros mediante una petición HTTP que termina en ciertos caracteres ilegales como ">", lo cual provoca que se procese y sirva un nombre de archivo diferente. | |
| Modificada | Alta (7.5) | 18% | — | Apache Http Server | 7/2/2003 | 16/6/2026 | Apache anteriores a 2.0.44, cuando corren sobre sistemas operativos Windows 9x y Me, permite a atacantes remotos causar una denegación de servicio o ejecutar código arbitrario mediane peticiones HTTP conteniendo nombres de dispositivo de MS-DOS. | |
| Modificada | Media (6.4) | 2.2% | — | Wasd Http Server | 31/12/2002 | 16/6/2026 | Format string vulnerability in PerlRTE_example1.pl in WASD 7.1, 7.2.0 through 7.2.3, and 8.0.0 allows remote attackers to execute arbitrary commands or crash the server via format strings in the $name variable. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Zeroo Http Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL GET request. | |
| Modificada | Media (6.4) | 1.8% | — | Tinyhttpd | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Gaztek Ghttpd | 31/12/2002 | 16/6/2026 | Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 1.8% | — | Summit Computer Networks LIL Http | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Lil' HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | |
| Modificada | Media (5) | 2.0% | — | Perl-httpd | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument. | |
| Modificada | Media (4.3) | 1.0% | — | Webster Http Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Webster HTTP Server allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 6.8% | 💥 Exploit | EZ Systems Httpbench | 31/12/2002 | 16/6/2026 | ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSite parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Nakata AN Httpd | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Apache Http Server | 31/12/2002 | 16/6/2026 | mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | An-httpd | 31/12/2002 | 16/6/2026 | Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username. | |
| Modificada | Alta (9.4) | 2.0% | — | Webster Http Server | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (9.4) | 52% | 💥 Exploit | Netdave Webster Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Media (4.6) | 1.1% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed… |