Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 324 respecto a la semana anterior
Críticas / altas1284▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 7.6% | 💥 Exploit | Hughes Technologies Libhttpd | 31/12/2002 | 16/6/2026 | Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Lonerunner Zeroo Http Server | 31/12/2002 | 16/6/2026 | Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary code via a long HTTP request. | |
| Modificada | Media (5) | 6.0% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Apache 1.3.19 running on HP Secure OS for Linux 1.0 allows remote attackers to cause "unexpected results" via an HTTP request. | |
| Modificada | Media (5) | 2.1% | — | IBM Http Server | 31/12/2002 | 16/6/2026 | IBM HTTP Server 1.0 on AS/400 allows remote attackers to obtain the path to the web root directory and other sensitive information, which is leaked in an error mesage when a request is made for a non-existent Java Server Page (JSP). | |
| Modificada | Crítica (9.8) | 9.0% | 💥 Exploit | Redshift Atphttpd | 31/12/2002 | 16/6/2026 | Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Apache Http Server | 31/12/2002 | 16/6/2026 | PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string. | |
| Modificada | Media (5) | 6.1% | — | Apache Http Server | 31/12/2002 | 16/6/2026 | Apache before 1.3.24, when writing to the log file, records a spoofed hostname from the reverse lookup of an IP address, even when a double-reverse lookup fails, which allows remote attackers to hide the original source of activities. | |
| Modificada | Alta (7.8) | 9.7% | 💥 Exploit | Apache Http ServerApache Tomcat | 31/12/2002 | 16/6/2026 | Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values. | |
| Modificada | Baja (2.6) | 0.56% | — | Apache Http Server | 4/11/2002 | 16/6/2026 | Apache 1.3.27 y anteriores, y posiblemente versiones posteriores, puede permitir a usuarios locales leer o modificar el fichero de contraseñas de Apache mediante un ataque de enlaces simbólicos en ficheros temporales cuando el administrador de Apache corre htpasswd o htdigest. | |
| Modificada | Alta (7.2) | 0.94% | — | Apache Http ServerDebian Linux | 11/10/2002 | 16/6/2026 | La tabla de puntuaciones (scoreboard) en memoria compartida del demonio HTTP en Apache 1.3.x anteriores a 1.3.27 permite a cualquier usuario corriendo con la UID de Apache enviar un señas SIGUSR1 a cualquier proceso como root, resultando en un a denegación de servicio (muerte de proceso) o posiblemente otros… | |
| Modificada | Media (5) | 9.5% | 💥 Exploit | Jetty Http Server | 11/10/2002 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en el CGIServlet en Jetty HHTP server anteriores a 4.1.0 permite a atacantes remotos leer ficheros arbitrarios mediante secuencias .. (punto punto barra invertida) en peticiones HTTP al directorio cgi-bin. | |
| Modificada | Media (6.8) | 95% | 💥 Exploit | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i+1 | 11/10/2002 | 16/6/2026 | Vulnerabilidad de comandos en sitios cruzados (cross-site scripting, XSS) en la página de error por defecto en Apache 2.0 antes de 2.0.43, y en 1.3.x hasta 1.3.26, cuando el parámetro UseCanonicalName está desactivado, y está presente el soporte para comodines DNS, permite a atacantes ejecutar comandos como otro… | |
| Modificada | Media (5) | 15% | — | Apache Http Server | 11/10/2002 | 16/6/2026 | Apache 2.0.42 permite a atacanes remotos ver el código fuente de un guión (script) CGI mediante una petición POST a un directorio con WebDAV y CGI activados. | |
| Modificada | Alta (7.5) | 21% | — | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i | 11/10/2002 | 16/6/2026 | Desbordamientos de búfer en el programa de soporte ApacheBench (ab.c) en Apache anteriores a 1.3.27, y Apache 2.x anteriores a 2.0.43, permite a un servidor web malicioso causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante una respuesta larga. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Summit Computer Networks LIL Http Server | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters. | |
| Modificada | Media (5) | 1.6% | — | Omnicron Omnihttpd | 4/10/2002 | 16/6/2026 | Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Summit Computer Networks LIL Http Server | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request. | |
| Modificada | Media (5) | 7.0% | — | Apache Http Server | 25/9/2002 | 16/6/2026 | mod_dav in Apache before 2.0.42 does not properly handle versioning hooks, which may allow remote attackers to kill a child process via a null dereference and cause a denial of service (CPU consumption) in a preforked multi-processing module. | |
| Modificada | Media (5) | 59% | 💥 Exploit | Apache Http Server | 5/9/2002 | 16/6/2026 | Apache 2.0 a 2.0.39 en Windows, OS2 y Netware, permite a atacantes remotos determinar la ruta completa del servidor mediante una petición de un fichero .var, donde el mensaje de error muestra muestra la ruta al archivo, o mediante un mensaje de error que ocurre cuando un script (proceso hijo) no puede ser invocado. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Acme Labs Thttpd | 12/8/2002 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en thttpd 2.20 y anteriores permite a atacantes remotos la ejecución arbitraria de rutinas mediante una URL a una página inexistente, lo cual provoca que thttpd inserte la rutina en un mensaje de error 404. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Apache Http Server | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to read arbitrary files and execute commands via .. (dot dot) sequences containing \ (backslash) characters. | |
| Modificada | Media (5) | 36% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | La librería ASN1 de Open SSL 0.9.6d y anterior, y 0.9.7-beta2 y anterior, permite que atacantes remotos provoquen una denegación de servicio por medio de codificaciones inválidas. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | W3C Cern Httpd | 12/8/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page. | |
| Modificada | Alta (7.5) | 90% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | Desbordamiento de búfer en OpenSSL 0.9.6d y anteriores, y 0.9.7-beta2 y anteriores, permite a atacantes remotos ejecutar código arbitrario mediante una clave maestra de cliente larga en SSL2 o un ID de sesión largo en SSL3 | |
| Modificada | Alta (7.5) | 8.2% | — | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | OpenSSL 0.9.6.d y anteriores, y 0.9.7-beta2 y anteriores, no manejan adecuadamente las representaciones ASCII de enteros en plataformas de 64 bits, lo que podría permitir a atacantes causar una denegación de servicio y posiblemente ejecutar código arbitrario. |