Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 12% | — | Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 14/12/2006 | 16/6/2026 | Desbordamiento de búfer basado en pila en el demonio NetBackup bpcd (bpcd.exe) en Symantec Veritas NetBackup 5.0 versiones anteriores a 5.0_MP7, 5.1 versiones anteriores a 5.1_MP6, y 6.0 versiones anteriores a 6.0_MP4, permite a atacantes remotos ejecutar código de su elección mediante una petición larga con una… | |
| Modificada | Alta (10) | 4.3% | — | Symantec Veritas Netbackup ClientSymantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 14/12/2006 | 16/6/2026 | El demonio NetBackup bpcd (bpcd.exe) en Symantec Veritas NetBackup 5.0 versiones anteriores a 5.0_MP7, 5.1 versiones anteriores a 5.1_MP6, y 6.0 versiones anteriores a 6.0_MP4, no comprueba apropiadamente comandos encadenados, que permite a atacantes remotos ejecutar código de su elección añadiendo comandos maliciosos… | |
| Modificada | Media (5) | 1.5% | — | RIM Blackberry Enterprise Server | 25/10/2006 | 16/6/2026 | Investigaciones sobre el Motion (RIM) BlackBerry Enterprise Server 4.1 SP2 anterior al Hotfix 1 para IBM Lotus Domino pueden permitir a atacantes remotos, con privilegios de organizador de eventos, causar la denegación de servicio (colgar la aplicación) a través del borrado de una convocatoria de reunión periódica… | |
| Modificada | Media (5) | 3.9% | — | Mono XSPSuse Open Enterprise ServerSuse Linux | 12/9/2006 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en el componente xsp en mod_mono en Mono/C# web server, es usado en SUSE Open-Enterprise-Server 1 y SUSE Linux 9.2 hasta la 10.0, permite a un atacante remoto leer ficheros de su elección a través de la secuencia ..(punto punto)en una respueta HTTP. | |
| Modificada | Media (5) | 1.6% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic. | |
| Modificada | Media (5) | 3.2% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | La implementación del servidor SSL en NILE.NLM en Novell NetWare 6.5 y Novell Open Enterprise Server (OES) a veces selecciona un cifrado débil en lugar de un cifrado más fuerte disponible, lo que facilita a atacantes remotos rastrear y descifrar una sesión SSL protegida. | |
| Modificada | Media (5) | 2.3% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | La implementación del servidor SSL en NILE.NLM en Novell NetWare 6.5 y Novell Open Enterprise Server (OES) permite a un cliente forzar el servidor para usar cifrado débil afirmando que se requiere un cifrado débil para la compatibilidad del cliente, lo que podría permitir a atacantes remotos descifrar contenidos de… | |
| Modificada | Alta (10) | 7.1% | — | Novell Linux DesktopNovell Open Enterprise Server | 27/2/2006 | 16/6/2026 | Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.1) | 2.7% | — | RIM Blackberry Enterprise Server | 18/2/2006 | 16/6/2026 | Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers… | |
| Modificada | Media (5) | 1.6% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap… | |
| Modificada | Media (5) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas. | |
| Modificada | Media (5) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion". | |
| Modificada | Alta (10) | 3.8% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the… | |
| Modificada | Alta (7.8) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and… | |
| Modificada | Alta (7.5) | 5.7% | — | Novell Open Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter. | |
| Modificada | Alta (7.8) | 3.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Router | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets. | |
| Modificada | Media (5) | 2.5% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 3.2% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbitrary code via certain data packets. | |
| Modificada | Alta (7.5) | 2.2% | — | RIM Blackberry Attachment ServiceRIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file. | |
| Modificada | Alta (10) | 60% | 💥 Exploit | Symantec Veritas Netbackup Data AND Business CenterSymantec Veritas Netbackup Enterprise Server Client | 12/10/2005 | 16/6/2026 | Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command. | |
| Modificada | Media (4.3) | 2.5% | — | IBM Lotus DominoIBM Lotus Domino Enterprise Server | 21/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters. | |
| Modificada | Baja (2.1) | 0.46% | — | Novell Open Enterprise ServerNovell Linux DesktopSuse Linux | 5/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en el kernel de Linux 2.6.x y 2.4.x permite que usuarios locales provoquen una denegación de servicio ("stack fault exception") mediante métodos desconocidos. | |
| Modificada | Baja (2.1) | 0.46% | — | Novell Open Enterprise ServerNovell Linux DesktopSuse Linux | 5/8/2005 | 16/6/2026 | Vulnerabilidad desconocida en el kernel de Linux permite que usuarios locales provoquen una denegación de servicio mediante ptrace | |
| Modificada | Media (5) | 1.1% | — | Symantec Veritas Netbackup Enterprise ServerSymantec Veritas Netbackup Server | 27/7/2005 | 16/6/2026 | NDMP server en Veritas NetBackup 5.1 permite que atacantes causen una denegación de servicio mediante un mensaje CONFIG con fecha fuera de rango, lo que provoca intento de acceso a puntero nulo. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. |