Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
1245 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.48% | — | IBM DB2 Universal Database | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in db2fmp in IBM DB2 7.x and 8.1 allows local users to execute arbitrary code via a long parameter. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Indexcor Ezdatabase | 17/12/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in ezDatabase 2.1.2 and earlier allows remote attackers to include arbitrary local files via ".." sequences in the p parameter. | |
| Modificada | Media (5) | 1.5% | — | Indexcor Ezdatabase | 17/12/2005 | 16/6/2026 | index.php in ezDatabase 2.1.2 and earlier allows remote attackers to obtain sensitive information via an invalid cat_id parameter, which leaks the full pathname in an error message. NOTE: these details are uncertain because the original report has terminology problems and lack of relevant details. The description is… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Indexcor Ezdatabase | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php for ezDatabase 2.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the db_id parameter. | |
| Modificada | Media (4.6) | 1.0% | 💥 Exploit | Appfluent Technology Database IDS | 8/12/2005 | 16/6/2026 | Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM DB2 Universal Database | 16/11/2005 | 16/6/2026 | IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Informix Dynamic Database Server | 16/11/2005 | 16/6/2026 | IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username. | |
| Modificada | Alta (7.5) | 4.7% | — | Oracle Database ServerOracle Database Server LiteOracle10gOracle8i+1 | 16/11/2005 | 16/6/2026 | Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Database ServerAIOracle Application ServerAI | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Single Sign-On in Oracle Database Server 10g up to 10.1.0.4.2 and Application Server 9.0.2.3 up to 9.0.4.2 has unknown impact and attack vectors, aka Oracle Vuln# DB33 and AS08. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Application ServerOracle Database Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Internet Directory in Oracle Database Server 9i up to 9.2.0.6 and Application Server 9.0.2.3 up to 10.1.2.0 has unknown impact and attack vectors, aka Oracle Vuln# DB32 and AS06. | |
| Modificada | Alta (10) | 5.6% | — | Oracle Application ServerOracle Database Server | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05. | |
| Modificada | Alta (10) | 4.1% | — | Oracle 10G Enterprise Manager Database ControlOracle Enterprise Manager Application Server Control | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Oracle Agent in Oracle Enterprise Manager 9.0.4.1 up to 10.1.0.4 has unknown impact and attack vectors, as identified by Oracle Vuln# EM01. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Database Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Database Scheduler in Oracle Database Server 10g up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB08. | |
| Modificada | Alta (10) | 2.9% | — | Oracle Database ServerAI | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Database Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01. | |
| Modificada | Alta (10) | 5.1% | — | Oracle Database Server | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vectors, aka Oracle Vuln# DB26. | |
| Modificada | Alta (10) | 5.9% | — | Oracle Database Server | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Database Server 9i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 in Change Data Capture; (2) DB06 in Data Guard Logical Standby; (3) DB10 in Locale; (4) DB12 in Materialized Views; (5) DB13 in Objects Extension; (6) DB15 in Oracle… | |
| Modificada | Alta (10) | 2.9% | — | Oracle Database ServerAI | 2/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Database Server 10g up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB02, (2) DB03, and (3) DB05 in Change Data Capture; (4) DB07 in Data Pump Export; and (5) DB18, (6) DB19, (7) DB20, (8) DB21, (9) DB22, (10) DB23, (11) DB24, and (12) DB25… | |
| Modificada | Alta (10) | 2.1% | — | Oracle Database ServerAI | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in Intelligent Agent in Oracle Database Server 9i up to 9.0.1.5 has unknown impact and attack vectors, aka Oracle Vuln# DB14. | |
| Modificada | Alta (10) | 3.8% | — | Oracle Database Server | 2/11/2005 | 16/6/2026 | Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Acid Analysis Console FOR Intrusion DatabasesSecureideas Basic Analysis AND Security Engine | 27/10/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via… | |
| Modificada | Media (5) | 22% | 💥 Exploit | Oracle Database Server | 14/10/2005 | 16/6/2026 | iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service (TNS listener stop) via an HTTP request with an sid parameter that contains a STOP command. | |
| Modificada | Baja (3.5) | 1.6% | — | Oracle Database Server | 14/10/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in iSQL*Plus (iSQLPlus) in Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to inject arbitrary web script or HTML via script in the "set markup HTML TABLE" command, which is executed when the user selects a table. | |
| Modificada | Alta (7.5) | 4.3% | — | Oracle Database Server | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in the SYS.DBMS_CDC_IPUBLISH.CREATE_SCN_CHANGE_SET procedure in Oracle Database Server 10g allows remote attackers to execute arbitrary SQL commands via the CHANGE_SET_NAME parameter. | |
| Modificada | Media (5) | 2.0% | — | Oracle Database Server | 2/5/2005 | 16/6/2026 | The DIRECTORY objects in Oracle 8i through Oracle 10g contain the location of a specific operating system directory, which allows users with read privileges to a DIRECTORY object to obtain sensitive information. |