Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2775▼ 14 respecto a la semana anterior
Críticas / altas1283▼ 250 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 205 respecto a la semana anterior
–

1147 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.33%—ISS Blackice PC Protection5/8/200616/6/2026
ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, y posiblemente anteriores versiones no monitorizan adecuadamente la integridad de la libreria pamversion.dll BlackICE, lo caul permite a un usuario local "trastornar" BlackICE a través del remplazo de pamversion.dll. NOTA: en la mayoría de los casos, el ataque no cruzaría…
ModificadaBaja (2.1)0.23%—Symantec On-demand AgentSymantec On-demand Protection5/8/200616/6/2026
Symantec On-Demand Agent (SODA) anterior a 2.5 MR2 Build 2157, y el módulo Virtual Desktop en Symantec On-Demand Protection (SODP) anterior 2.6 Build 2233, no encripta de forma adecuada archivos que estén sujetos a la política de encriptación automática, lo cual permitiría a un usuario local leer datos sensible a…
ModificadaMedia (5)2.4%—ISS Blackice PC ProtectionISS Blackice Server ProtectionISS Proventia DesktopISS Realsecure Desktop+627/7/200616/6/2026
La funcionalidad SMB Mailslot en PAM en múltiples productos ISS con XPU (24.39/1.78/epj/x.x.x.1780), incluyendo Proventia A, G, M, Server, y Desktop, BlackICE PC y Server Protection 3.6, y RealSecure 7.0,permiten a atacantes remotos provocar denegación de servicio (bucle infinito) a través de paquetes SMB manipulados…
ModificadaAlta (7.5)1.7%—Fileprotection Express4/5/200616/6/2026
FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1.
ModificadaMedia (5)12%💥 ExploitBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+319/1/200616/6/2026
The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business…
ModificadaMedia (5)3.8%—Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+319/1/200616/6/2026
The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection…
ModificadaAlta (7.2)0.37%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop31/12/200516/6/2026
ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary…
ModificadaMedia (4.6)0.44%—Sygate Technologies Protection Agent28/12/200516/6/2026
SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local users to obtain management control over the agent by executing the GUI (SmcGui.exe) and then killing the process, which causes the privileged management GUI to launch.
ModificadaMedia (6.4)1.4%—Proofpoint Protection Server31/12/200416/6/2026
The embedded MySQL 4.0 server for Proofpoint Protection Server does not require a password for the root user of MySQL, which allows remote attackers to read or modify the backend database.
ModificadaMedia (4.6)0.43%—ISS Blackice PC Protection31/12/200416/6/2026
The upgrade for BlackICE PC Protection 3.6 and earlier sets insecure permissions for .INI files such as (1) blackice.ini, (2) firewall.ini, (3) protect.ini, or (4) sigs.ini, which allows local users to modify BlackICE configuration or possibly execute arbitrary code by exploiting vulnerabilities in the .INI parsers.
ModificadaMedia (4.6)0.42%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop31/12/200416/6/2026
Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver17/8/200416/6/2026
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
ModificadaAlta (7.1)0.85%💥 ExploitISS Blackice PC ProtectionISS Blackice Server Protection11/8/200416/6/2026
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control permissions, which allows local users to cause a denial of service (crash) or modify configuration, as demonstrated by modifying firewall.ini to contain a large firewall…
ModificadaAlta (7.5)73%💥 ExploitISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/4/200416/6/2026
Múltiples desbordamientos de búfer basado en la pila en las rutinas de análisis de ICQ en el componente ISS Protocol Analysis Module (PAM), utilizado en varios productos RealSecure, Proventia y BlackICE, permite a atacantes remotos ejecutar código arbitrario mediante un respuesta SRV_MULTI conteniendo un paquete de…
ModificadaAlta (7.5)8.0%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/3/200416/6/2026
Desbordamiento de búfer basado en la pila en el Módulo de análisis de Protocolos (PAM) de ISS, usado en ciertas versiones de RealSecure Network 7.0 y Server Sensor 7.0, Proventia series A, G, y M, Desktop 7.0 y 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, y BlackICE Server Protection…
ModificadaCrítica (9.8)1.6%—Pedestalsoftware Integrity Protection Driver31/12/200316/6/2026
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst…
ModificadaMedia (4.3)1.4%—IBM Internet Security Systems Blackice DefenderISS Blackice Server Protection31/12/200316/6/2026
BlackICE Defender 2.9.cap and Server Protection 3.5.cdf, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
ModificadaBaja (2.1)0.33%—Pedestal Software Integrity Protection Driver31/12/200316/6/2026
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.
ModificadaBaja (2.1)0.35%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
ModificadaMedia (5)2.7%💥 ExploitJohn Drake Killer Protection31/12/200216/6/2026
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php.
ModificadaAlta (7.5)1.7%—Intel High-bandwidth Digital Content Protection20/11/200116/6/2026
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.