Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2758▼ 17 respecto a la semana anterior
Críticas / altas1269▼ 209 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
1234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | SUN ONE Application Server | 18/3/2003 | 16/6/2026 | Desbordamiento de búfer en el conector gxnsapi6.dll del Módulo Conector de Sun ONE Application Server anterior a 6.5 permite a atacantes remotos ejecutar código arbitrario mediante una URL larga en una petición HTTP. | |
| Modificada | Alta (7.5) | 15% | — | Oracle Application Server | 3/3/2003 | 16/6/2026 | Vulnerabilidad de cadena de formato en ciertas modificaciones de terceros a mod_dav para el registro de mesajes de pasarela erroneos (por ejemplo Oracle 9i Application Server 9.0.2) permite a atacantes remotos ejecutar código arbitrario mediante una URI de destino que fuerza una respuesta "502 Bad Gateway", lo que… | |
| Modificada | Media (5) | 3.7% | — | HP Application Server | 31/12/2002 | 16/6/2026 | HP Application Server 8.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). | |
| Modificada | Media (5) | 4.4% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | The Apache configuration file (httpd.conf) in Oracle 9i Application Server (9iAS) uses a Location alias for /perl directory instead of a ScriptAlias, which allows remote attackers to read the source code of arbitrary CGI files via a URL containing the /perl directory instead of /cgi-bin. | |
| Modificada | Media (6.4) | 5.4% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2. | |
| Modificada | Media (5) | 2.5% | — | Orionserver Orion Application Server | 31/12/2002 | 16/6/2026 | Orion Application Server 1.5.3, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). | |
| Modificada | Alta (7.5) | 7.1% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails. | |
| Modificada | Media (4.3) | 1.7% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field. | |
| Modificada | Alta (7.5) | 7.3% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 4.5% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). | |
| Modificada | Alta (7.5) | 7.7% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter. | |
| Modificada | Alta (7.5) | 1.4% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access. | |
| Modificada | Media (4.3) | 1.6% | — | Oracle Application Server | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Oracle Application Server | 4/11/2002 | 16/6/2026 | El módulo de administración de Oracle Web Cache en Oracle9iAS (9i Application Suite) 9.0.2 permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición HTTP GET conteniendo una secuencia ".." (punto punto), o una petición HTTP GET con un Transfer-Encoding troceado al que le faltan datos. | |
| Modificada | Alta (7.5) | 21% | — | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i | 11/10/2002 | 16/6/2026 | Desbordamientos de búfer en el programa de soporte ApacheBench (ab.c) en Apache anteriores a 1.3.27, y Apache 2.x anteriores a 2.0.43, permite a un servidor web malicioso causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante una respuesta larga. | |
| Modificada | Media (5) | 3.4% | — | IBM Websphere Application Server | 11/10/2002 | 16/6/2026 | IBM Websphere 4.0.3 permite a atacantes remotos causar una denegación de servicio (caída), y posiblemente ejecutar código arbitrario mediante una petición HTTP con cabeceras HTTP largas, como "Host". | |
| Modificada | Media (6.8) | 95% | 💥 Exploit | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i+1 | 11/10/2002 | 16/6/2026 | Vulnerabilidad de comandos en sitios cruzados (cross-site scripting, XSS) en la página de error por defecto en Apache 2.0 antes de 2.0.43, y en 1.3.x hasta 1.3.26, cuando el parámetro UseCanonicalName está desactivado, y está presente el soporte para comodines DNS, permite a atacantes ejecutar comandos como otro… | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | Netscape Enterprise ServerSUN Iplanet WEB ServerSUN ONE Application ServerSUN ONE WEB Server | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks. | |
| Modificada | Alta (7.5) | 9.5% | — | Oracle Application ServerOracle Reports | 4/10/2002 | 16/6/2026 | Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter. | |
| Modificada | Alta (7.5) | 90% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | Desbordamiento de búfer en OpenSSL 0.9.6d y anteriores, y 0.9.7-beta2 y anteriores, permite a atacantes remotos ejecutar código arbitrario mediante una clave maestra de cliente larga en SSL2 o un ID de sesión largo en SSL3 | |
| Modificada | Media (5) | 36% | 💥 Exploit | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | La librería ASN1 de Open SSL 0.9.6d y anterior, y 0.9.7-beta2 y anterior, permite que atacantes remotos provoquen una denegación de servicio por medio de codificaciones inválidas. | |
| Modificada | Alta (7.5) | 8.2% | — | OpensslOracle Application ServerOracle Corporate Time Outlook ConnectorOracle Http Server+1 | 12/8/2002 | 16/6/2026 | OpenSSL 0.9.6.d y anteriores, y 0.9.7-beta2 y anteriores, no manejan adecuadamente las representaciones ASCII de enteros en plataformas de 64 bits, lo que podría permitir a atacantes causar una denegación de servicio y posiblemente ejecutar código arbitrario. | |
| Modificada | Alta (7.5) | 19% | — | Oracle Application Server | 3/7/2002 | 16/6/2026 | Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet). | |
| Modificada | Media (5) | 5.7% | — | Oracle Application ServerOracle Application Server WEB CacheOracle9i | 3/7/2002 | 16/6/2026 | Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages. |