Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

137 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.1%—Openstack Swift3/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
ModificadaMedia (5.8)0.73%—Openstack Swift18/2/201417/6/2026
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.9%—Openstack Swift23/1/201417/6/2026
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
ModificadaMedia (4)1.7%—Openstack FolsomOpenstack GrizzlyOpenstack HavanaOpenstack Swift20/8/201316/6/2026
OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service ("superfluous" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.
ModificadaCrítica (9.8)6.6%—Openstack SwiftFedoraproject FedoraRedhat Gluster Storage Management ConsoleRedhat Gluster Storage Server FOR On-premise+322/10/201216/6/2026
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.
ModificadaAlta (9.3)4.9%💥 ExploitTricerasoft Swift Ultralite18/9/200916/6/2026
Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.
ModificadaAlta (7.1)2.6%—Symantec Scan EngineSymantec Antivirus ClearswiftSymantec Antivirus Filtering Domino MPESymantec Antivirus Messaging+628/2/200816/6/2026
Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).
ModificadaMedia (6.8)3.7%—Symantec Scan EngineSymantec Antivirus Filtering Domino MPESymantec Antivirus Network Attached StorageSymantec Antivirus Scan Engine+628/2/200816/6/2026
Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content…
ModificadaAlta (10)8.4%—Swiftview Viewer5/2/200816/6/2026
Multiple stack-based buffer overflows in SwiftView Viewer before 8.3.5, as used by SwiftView and SwiftSend, allow remote attackers to execute arbitrary code via unspecified vectors to the (1) svocx.ocx ActiveX control or the (2) npsview.dll plugin for Mozilla and Firefox.
ModificadaAlta (7.5)2.0%—NCH Software Swift Sound WEB Dictate7/9/200616/6/2026
NCH Swift Sound Web Dictate 1.02 allows remote attackers to bypass authentication via a null password.
ModificadaMedia (5)1.6%—Clearswift Mimesweeper FOR WEB12/7/200616/6/2026
Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to cause a denial of service (crash) via an encrypted archived .RAR file, which triggers a scan error and causes the Web Policy Engine service to terminate.
ModificadaMedia (4.3)1.8%—Clearswift Mimesweeper FOR WEB12/7/200616/6/2026
Cross-site scripting (XSS) vulnerability in Clearswift MIMEsweeper for Web before 5.1.15 Hotfix allows remote attackers to inject arbitrary web script or HTML via the URL, which is reflected back in an error message when trying to access a blocked web site.
ModificadaMedia (5)1.9%—Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp24/6/200616/6/2026
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed…
ModificadaAlta (7.5)1.7%—Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp24/6/200616/6/2026
Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to bypass the "text analysis", possibly bypassing SPAM and other filters, by sending an e-mail specifying a non-existent or unrecognized character set.
ModificadaMedia (5)1.7%—Clearswift Mimesweeper FOR WEB28/12/200516/6/2026
Clearswift MIMEsweeper For Web (a.k.a. WEBsweeper) 4.0 through 5.1 allows remote attackers to bypass filtering via a URL that does not include a .exe extension but returns an executable file.
ModificadaMedia (5)1.6%—Clearswift Mailsweeper31/12/200416/6/2026
Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.
ModificadaMedia (4.3)1.1%—Clearswift Mailsweeper Business Suite IClearswift Mailsweeper Business Suite IIClearswift Mailsweeper FOR SmtpClearswift Mimesweeper FOR WEB31/12/200416/6/2026
Clearswift MIMEsweeper 5.0.5, when it has been upgraded from MAILsweeper for SMTP version 4.3 or MAILsweeper Business Suite I or II, allows remote attackers to bypass scanning by including encrypted data in a mail message, which causes the message to be marked as "Clean" instead of "Encrypted".
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters,…
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use fields that use RFC2047 encoding, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.0%—Clearswift Mailsweeper28/9/200416/6/2026
Clearswift MAILsweeper before 4.3.15 does not properly detect and filter ZIP 6.0 encoded files, which allows remote attackers to bypass intended policy.
Orbitaley — Vulnerabilidades