Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.1% | — | Oracle Application Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01. | |
| Modificada | Alta (10) | 4.1% | — | Oracle 10G Enterprise Manager Database ControlOracle Enterprise Manager Application Server Control | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Application Server | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Application Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in the HTTP Server in Oracle Application Server 1.0 up to 9.0.2.3 has unknown impact and attack vectors, as identified by Oracle Vuln# AS04. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Database ServerAIOracle Application ServerAI | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Application Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Web Cache in Oracle Application Server 1.0 up to 9.0.4.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS13. | |
| Modificada | Alta (10) | 5.6% | — | Oracle Application ServerOracle Database Server | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05. | |
| Modificada | Alta (10) | 5.6% | — | Oracle Application Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in SQL*ReportWriter in Oracle Application Server 9.0 up to 9.0.2.1 has unknown impact and attack vectors, as identified by Oracle Vuln# AS10. | |
| Modificada | Media (4.3) | 21% | 💥 Exploit | Oracle Application ServerOracle9i | 14/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request. | |
| Modificada | Baja (2.6) | 6.5% | — | Hitachi Cosminexus Application ServerApache Tomcat | 6/10/2005 | 16/6/2026 | The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an information leak when "unsuitable request body… | |
| Modificada | Media (4.3) | 0.95% | — | Orionserver Orion Application Server | 20/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Orion 1.3.8 and 1.4.5 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting 404 error page. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Websphere Application Server | 5/7/2005 | 16/6/2026 | IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes WebSphere to incorrectly handle and forward the body of… | |
| Modificada | Media (4.3) | 4.9% | — | Oracle Application Server | 5/7/2005 | 16/6/2026 | Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and… | |
| Modificada | Alta (7.5) | 3.2% | — | IBM Websphere Application Server | 3/6/2005 | 16/6/2026 | Buffer overflow in the administrative console in IBM WebSphere Application Server 5.x, when the global security option is enabled, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (4.6) | 38% | — | Oracle Application ServerOracle10g | 11/5/2005 | 16/6/2026 | The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user. | |
| Modificada | Alta (7.5) | 3.2% | — | Oracle Application ServerOracle10gOracle9i | 11/5/2005 | 16/6/2026 | Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection. | |
| Modificada | Media (6.8) | 20% | 💥 Exploit | Oracle Application Server WEB Cache | 3/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Oracle Application Server WEB Cache | 3/5/2005 | 16/6/2026 | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter. | |
| Modificada | Alta (7.5) | 31% | 💥 Exploit | Oracle Application Server | 3/5/2005 | 16/6/2026 | The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778. | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | IBM Websphere Application Server | 2/5/2005 | 16/6/2026 | IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine. | |
| Modificada | Media (4.3) | 1.8% | — | SUN Java System Application Server | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (5) | 2.1% | — | IBM Websphere Application Server | 2/5/2005 | 16/6/2026 | Vulnerabilidad desconocida en IBM Websphere Application Server 5.0, 5.1, y 6.0 cuando es ejecutado en Windows, permite a atacantes remotos obtener el código fuente de Java Server Pages (.jsp) mediante una URL alterada que hace que la página sea procesada por el fichero que sirve el servlet en lugar de por el motor JSP. | |
| Modificada | Media (5) | 2.6% | — | Oracle Application ServerOracle9i | 31/12/2004 | 16/6/2026 | The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD. | |
| Modificada | Media (5) | 1.6% | — | SUN Java System Application ServerSUN Java System WEB Server | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. |