Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▼ 317 respecto a la semana anterior
Críticas / altas1288▼ 233 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
1212 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 95% | 💥 Exploit | Apache Http ServerDebian Linux | 3/7/2002 | 16/6/2026 | Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. | |
| Modificada | Media (5) | 1.5% | — | Summit Computer Networks LIL Http Server | 31/5/2002 | 16/6/2026 | Lil HTTP Server 2.1 permite a atacantes remotos leer ficheros protegidos por contraseña mediante un /./ (barra punto barra) en la petición HTTP. | |
| Modificada | Media (5) | 7.2% | — | Apache Http Server | 29/5/2002 | 16/6/2026 | PHP para windows, cuando se ha instalado en Apache 2.0.28 beta como una CGI aislada, permite a atacantes remotos obtener el camino físico del php.exe mediante argumentos intencionados tales como /123, lo cual permite que se muestre el path absoluto en el emensaje de error. | |
| Modificada | Media (5) | 7.4% | — | Apache Http Server | 29/5/2002 | 16/6/2026 | PHP, cuando se instala con Apache y se configura para buscar index.php como la página web por defecto, permite a los atacantes remotos que obtengan el path completo del servidor por medio del método HTTP OPTIONS, lo cual revelará el nombre del path en el mensaje de error correspondiente. | |
| Modificada | Alta (7.5) | 4.0% | — | Apache Http ServerUsanet Creations Makebid Auction Deluxe | 29/5/2002 | 16/6/2026 | Vulnerabilidad de comandos en sitios cruzados en auction.pl de MakeBid Auction Deluxe 3.30 permite que atacantes remotos obtengan información de otros usuarios por medio de los campos de formulario (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10)… | |
| Modificada | Media (5) | 12% | — | Apache Http Server | 6/5/2002 | 16/6/2026 | The ap_log_rerror function in Apache 2.0 through 2.035, when a CGI application encounters an error, sends error messages to the client that include the full path for the server, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 50% | 💥 Exploit | Apache Http Server | 21/3/2002 | 16/6/2026 | El servidor Apache, en sus verisones para Win32 1.3.24 y anteriores, y 2.0.x hasta la 2.0.34-beta, permite que atacantes remotos ejecuten cualquier comando a través del metacaracter "|" de la shell. Estos comandos vienen como argumentos a scrips .bat o .cmd. A su vez estos scripts pasan sin filtrado al intérprete de… | |
| Modificada | Baja (2.1) | 0.70% | — | Apache Http Server | 31/12/2001 | 16/6/2026 | mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication. | |
| Modificada | Crítica (9.8) | 4.8% | — | Acme Thttpd | 31/12/2001 | 16/6/2026 | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 3.6% | — | Apache Http Server | 31/12/2001 | 16/6/2026 | The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep. | |
| Modificada | Alta (7.8) | 4.1% | — | Cherokee Httpd | 29/12/2001 | 16/6/2026 | Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 3.4% | — | Cherokee Httpd | 29/12/2001 | 16/6/2026 | Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Gaztek Ghttp | 6/12/2001 | 16/6/2026 | Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c. | |
| Modificada | Alta (7.5) | 7.8% | — | Apache Http ServerMandrakesoft Mandrake Single Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 28/11/2001 | 16/6/2026 | The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. | |
| Modificada | Media (5) | 1.9% | — | Acme Thttpd | 13/11/2001 | 16/6/2026 | Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | |
| Modificada | Media (5) | 2.5% | — | Acme Mini Httpd | 13/11/2001 | 16/6/2026 | Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | |
| Modificada | Media (5) | 12% | — | Apache Http Server | 30/10/2001 | 16/6/2026 | split-logfile in Apache 1.3.20 allows remote attackers to overwrite arbitrary files that end in the .log extension via an HTTP request with a / (slash) in the Host: header. | |
| Modificada | Media (5) | 6.8% | — | Apache Http Server | 30/10/2001 | 16/6/2026 | Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters. | |
| Modificada | Media (5) | 1.7% | — | Omnicron Omnihttpd | 18/10/2001 | 16/6/2026 | Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Apache Http Server | 18/10/2001 | 16/6/2026 | Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters. | |
| Modificada | Media (5) | 6.3% | 💥 Exploit | Omnicron Omnihttpd | 18/10/2001 | 16/6/2026 | OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). | |
| Modificada | Media (5) | 57% | 💥 Exploit | Apache Http Server | 1/10/2001 | 16/6/2026 | Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a URL containing the "M=D" query string. | |
| Modificada | Alta (7.2) | 0.58% | — | IBM Http Server SSL Module Common | 31/8/2001 | 16/6/2026 | ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class. | |
| Modificada | Media (5) | 4.3% | — | Apache Http Server | 31/8/2001 | 16/6/2026 | Apache with mod_rewrite enabled on most UNIX systems allows remote attackers to bypass RewriteRules by inserting extra / (slash) characters into the requested path, which causes the regular expression in the RewriteRule to fail. | |
| Modificada | Media (5) | 1.7% | — | Omnicron Omnihttpd | 22/8/2001 | 16/6/2026 | Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request. |