Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

1245 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)95%💥 ExploitApache Http ServerOracle Application ServerOracle Database ServerOracle8i+111/10/200216/6/2026
Vulnerabilidad de comandos en sitios cruzados (cross-site scripting, XSS) en la página de error por defecto en Apache 2.0 antes de 2.0.43, y en 1.3.x hasta 1.3.26, cuando el parámetro UseCanonicalName está desactivado, y está presente el soporte para comodines DNS, permite a atacantes ejecutar comandos como otro…
ModificadaMedia (5)2.7%—Oracle Database ServerOracle9i5/9/200216/6/2026
El servidor SQL*NET para Oracle 9i 9.0.x y 9.2 permite a atacantes remotos causar una denegación de sevicio (caída) mediante ciertas peticiones de depuración que no son adecuadamente manejadas por la característica de depuración
ModificadaAlta (7.5)14%—Oracle Database ServerOracle8i5/9/200216/6/2026
Vulnerabilidad de formato de cadenas en la utilidad Oracle Listener Control (lsnrctl) en Oracle 9.2, 9.0, 8.1 y 7.3.4 permite a atacantes remotos ejecutar código arbitrario el sitstema Oracle DBA mediante la introducción de cadenas de formato en ciertas entradas en fichero de configuración listener.ora
ModificadaAlta (7.5)8.7%—Oracle Database ServerOracle8iOracle9i3/7/200216/6/2026
Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process.
ModificadaBaja (2.1)0.49%—Oracle Database Server6/12/200116/6/2026
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File…
ModificadaAlta (7.2)2.1%💥 ExploitOracle Database Server6/12/200116/6/2026
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability."
ModificadaMedia (4.6)0.56%—Oracle Database Server6/12/200116/6/2026
Vulnerabilidad en Oracle Label Security en Oracle 8.1.7 y 9.0.1 cuando se usan la funcionalidad de auditar, SET_LABEL o SQL*Predicate, permite a usuarios locales ganar privilegios adicionales.
ModificadaMedia (4.6)1.7%💥 ExploitOracle Database Server30/11/200116/6/2026
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.
ModificadaMedia (4.6)0.56%—Oracle Database Server29/11/200116/6/2026
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp.
ModificadaAlta (10)5.7%—Tooltalk Database Server30/10/200116/6/2026
Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.
ModificadaAlta (7.2)2.0%—Oracle Database Server31/8/200116/6/2026
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
ModificadaBaja (2.1)0.58%—Oracle Database Server31/8/200116/6/2026
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
ModificadaMedia (5)2.1%—Oracle Database ServerOracle8i21/7/200116/6/2026
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.
ModificadaMedia (5)1.6%—IBM DB2 Universal Database11/7/200116/6/2026
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.
ModificadaMedia (5)2.8%—Oracle Database Server12/3/200116/6/2026
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.
ModificadaAlta (7.5)2.8%💥 ExploitIBM DB2 Universal Database16/2/200116/6/2026
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database.
ModificadaBaja (2.1)1.2%💥 ExploitIBM DB2 Universal Database16/2/200116/6/2026
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
ModificadaAlta (7.5)1.6%—Pccs-linux Mysqldatabase Admin Tool20/10/200016/6/2026
PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password.
ModificadaMedia (4.6)1.1%💥 ExploitOracle Database ServerOracle8i16/8/199916/6/2026
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script.
ModificadaMedia (4.6)1.9%—Oracle Database Assistant4/3/199916/6/2026
Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.
Orbitaley — Vulnerabilidades