Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2771▲ 6 respecto a la semana anterior
Críticas / altas1285▼ 246 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

1223 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.3%💥 ExploitDigital Illusions Battlefield 1942Digital Illusions Battlefield Vietnam10/1/200516/6/2026
Battlefield 1942 1.6.19 and earlier, and Battlefield Vietnam 1.2 and earlier, allows a remote master server to cause a denial of service (client crash) via a server reply that contains a large numplayers value, which triggers a null dereference.
ModificadaMedia (5)7.5%💥 ExploitDigital Mappings Systems Pop3 Server31/12/200416/6/2026
Buffer overflow in pop3svr.exe for DMS POP3 1.5.3.27 and earlier allows remote attackers to cause a denial of service (service crash) via a long (1) username or (2) password.
ModificadaBaja (2.1)0.34%—Keene Digital Media ServerAI31/12/200416/6/2026
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system.
ModificadaAlta (9.3)49%💥 ExploitMicrosoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+2028/9/200416/6/2026
Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria.
ModificadaAlta (10)15%💥 ExploitEngardelinux Guardian Digital WebtoolUserminWebmin3/3/200316/6/2026
miniserv.pl en Webmin anterior a 1.070 y Usermin antes de 1.000 no maneja adecuadamente metacaractéres como avance de línea y retorno de carro (CRLF) en cadenas codificadas en Base-64 durante la autenticación básica, lo que permite a atacantes remotos suplantar un ID de sesión y ganar privilegios de root.
ModificadaMedia (5)1.8%—RCA Digital Cable Modem31/12/200216/6/2026
The RCA Digital Cable Modems DCM225 and DCM225E allow remote attackers to cause a denial of service (modem device reset) by connecting to port 80 on the 10.0.0.0/8 device.
ModificadaMedia (5)1.4%—RCA Digital Cable Modem31/12/200216/6/2026
RCA Digital Cable Modem DCM225 and DCM225E, and other modems that must conform to the Data-over-Cable Service Interface Specifications DOCSIS standard, uses the "public" community string for SNMP access, which allows remote attackers to read or write MIB information.
ModificadaMedia (4.6)1.6%💥 ExploitAdobe Digital Editions4/10/200216/6/2026
Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files.
ModificadaAlta (7.2)1.0%💥 ExploitCompaq Tru64Digital OSF 14/10/200216/6/2026
Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
ModificadaBaja (2.1)0.41%—Adobe Digital Editions4/10/200216/6/2026
Adobe eBook Reader 2.1 and 2.2 allows a user to copy eBooks to other systems by using the backup feature, capturing the encryption Challenge, and using the appropriate hash function to generate the activation code.
ModificadaAlta (7.2)0.46%—Digital OSF 1Digital Ultrix4/10/200216/6/2026
Buffer overflow in inc mail utility for Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long MH environment variable.
ModificadaAlta (7.2)0.46%—Digital OSF 14/10/200216/6/2026
Buffer overflow in uucp in Compaq Tru64/OSF1 3.x allows local users to execute arbitrary code via a long source (-s) command line parameter.
ModificadaAlta (7.5)1.7%—Intel High-bandwidth Digital Content Protection20/11/200116/6/2026
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.
ModificadaAlta (7.5)1.8%—Eeye Digital Security Securells14/8/200116/6/2026
eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.
ModificadaAlta (7.5)2.0%—Eeye Digital Security SecureiisEeye Digital Security Securells14/8/200116/6/2026
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be…
ModificadaAlta (7.2)0.71%💥 ExploitDigital Unix27/6/200116/6/2026
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).
ModificadaBaja (2.6)2.7%💥 ExploitEeye Digital Security Iris26/3/200116/6/2026
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.
ModificadaMedia (5)1.8%—Debian LinuxDigital UnixNetbsdRedhat Linux+112/3/200116/6/2026
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
ModificadaAlta (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+1112/3/200116/6/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
ModificadaMedia (5)1.8%—Debian LinuxDigital UnixNetbsdRedhat Linux+112/3/200116/6/2026
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
ModificadaMedia (6.4)1.3%—Digital Unix14/11/200016/6/2026
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.
ModificadaMedia (5)2.5%💥 ExploitEeye Digital Security IrisSpynet Capturenet20/10/200016/6/2026
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.
ModificadaMedia (5)3.1%💥 ExploitLeafdigital Leafchat25/6/200016/6/2026
LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
ModificadaAlta (7.5)2.2%—CDEDigital UnixIBM AIXSUN Solaris+113/9/199916/6/2026
The ToolTalk ttsession daemon uses weak RPC authentication, which allows a remote attacker to execute commands.
ModificadaAlta (7.2)0.84%💥 ExploitCDEDigital UnixIBM AIXSUN Solaris+113/9/199916/6/2026
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.