Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

214 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.42%—Broadcom Internet Security SuiteCA Host Based Intrusion Prevention SystemCA Internet Security Suite 2008CA Personal Firewall 2007+112/8/200816/6/2026
The kmxfw.sys driver in CA Host-Based Intrusion Prevention System (HIPS) r8, as used in CA Internet Security Suite and Personal Firewall, does not properly verify IOCTL requests, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted request.
ModificadaAlta (7.5)1.2%💥 ExploitMojoscripts Mojopersonals31/7/200816/6/2026
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.2)0.37%—Comodo Personal Firewall30/4/200816/6/2026
Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper…
ModificadaAlta (9.3)3.9%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
ModificadaAlta (9.3)6.0%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
ModificadaMedia (4.4)0.32%—Online Armor Personal Firewall19/9/200716/6/2026
Online Armor Personal Firewall 2.0.1.215 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1)…
ModificadaMedia (6.9)1.1%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+215/7/200716/6/2026
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt…
ModificadaAlta (9.3)3.7%—F-secure Anti-virusF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server SecurityF-secure Internet Security+220/6/200716/6/2026
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
ModificadaAlta (7.2)0.32%—Checkpoint ZonealarmComodo Firewall PROComodo Personal Firewall16/5/200716/6/2026
Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one,…
ModificadaAlta (7.2)0.32%—Comodo Firewall PROComodo Personal Firewall16/5/200716/6/2026
Comodo Firewall Pro 2.4.18.184 and Comodo Personal Firewall 2.3.6.81, and probably older Comodo Firewall versions, do not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass…
ModificadaAlta (10)65%💥 ExploitSymantec Norton Internet SecuritySymantec Norton Personal Firewall16/5/200716/6/2026
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
ModificadaAlta (7.8)3.2%—AmavisAvast AntivirusAvast Antivirus HomeAvast Antivirus Professional+99/5/200716/6/2026
unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaAlta (7.8)2.0%—Avira Antivir Personal9/5/200716/6/2026
avpack32.dll before 7.3.0.6 in Avira AntiVir allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaMedia (4.9)1.7%💥 ExploitSymantec AntivirusSymantec Client SecuritySymantec Norton 360Symantec Norton Antispam+42/4/200716/6/2026
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2)…
ModificadaMedia (4.9)0.40%—Symantec Norton Personal Firewall16/3/200716/6/2026
The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.1.7, and possibly other products using symevent.sys 12.0.0.20, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data, a reintroduction of CVE-2006-4855.
ModificadaBaja (1.9)0.86%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+216/3/200716/6/2026
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2005 and 2006, AntiVirus Corporate Edition 3.0.x through 10.1.x, and other Norton products, allows local users to cause a denial of service (system crash) by sending crafted data to the driver's…
ModificadaBaja (3.5)1.2%—Cisco ACS Solution EngineCiscoworksCisco IP CommunicatorCisco Meetingplace+1416/3/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified…
ModificadaAlta (7.5)5.0%💥 ExploitDxmsoft XM Easy Personal FTP Server2/3/200716/6/2026
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.
ModificadaMedia (6.8)0.66%💥 ExploitSunbelt Kerio Personal Firewall5/1/200716/6/2026
Sunbelt Kerio Personal Firewall (SKPF) 4.3.268 and 4.3.246, and possibly other versions allows local users to provide a Trojan horse iphlpapi.dll to SKPF by placing it in the installation directory.
ModificadaAlta (7.5)1.2%—Personal .net Portal29/12/200616/6/2026
Unspecified vulnerability in the tab editor for Personal .NET Portal before 2.0.0 has unknown impact and attack vectors related to a "Security leak."
ModificadaMedia (5)2.2%💥 ExploitDxmsoft XM Easy Personal FTP Server27/12/200616/6/2026
Format string vulnerability in XM Easy Personal FTP Server 5.0.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in a long PORT command. NOTE: this issue might be related to CVE-2006-2226.
ModificadaMedia (5)3.4%💥 ExploitDxmsoft XM Easy Personal FTP Server27/12/200616/6/2026
Format string vulnerability in XM Easy Personal FTP Server 5.2.1 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the USER command or certain other available or nonexistent commands. NOTE: It was later reported that 5.3.0 is also vulnerable.
ModificadaAlta (7.2)0.33%—AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+218/12/200616/6/2026
Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
ModificadaAlta (7.2)0.33%—AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+218/12/200616/6/2026
Filseclab Personal Firewall 3.0.0.8686 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
ModificadaAlta (7.2)0.33%—AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+218/12/200616/6/2026
AntiHook 3.0.0.23 - Desktop relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
Orbitaley — Vulnerabilidades