Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
1245 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 95% | 💥 Exploit | Apache Http ServerOracle Application ServerOracle Database ServerOracle8i+1 | 11/10/2002 | 16/6/2026 | Vulnerabilidad de comandos en sitios cruzados (cross-site scripting, XSS) en la página de error por defecto en Apache 2.0 antes de 2.0.43, y en 1.3.x hasta 1.3.26, cuando el parámetro UseCanonicalName está desactivado, y está presente el soporte para comodines DNS, permite a atacantes ejecutar comandos como otro… | |
| Modificada | Media (5) | 2.7% | — | Oracle Database ServerOracle9i | 5/9/2002 | 16/6/2026 | El servidor SQL*NET para Oracle 9i 9.0.x y 9.2 permite a atacantes remotos causar una denegación de sevicio (caída) mediante ciertas peticiones de depuración que no son adecuadamente manejadas por la característica de depuración | |
| Modificada | Alta (7.5) | 14% | — | Oracle Database ServerOracle8i | 5/9/2002 | 16/6/2026 | Vulnerabilidad de formato de cadenas en la utilidad Oracle Listener Control (lsnrctl) en Oracle 9.2, 9.0, 8.1 y 7.3.4 permite a atacantes remotos ejecutar código arbitrario el sitstema Oracle DBA mediante la introducción de cadenas de formato en ciertas entradas en fichero de configuración listener.ora | |
| Modificada | Alta (7.5) | 8.7% | — | Oracle Database ServerOracle8iOracle9i | 3/7/2002 | 16/6/2026 | Oracle 8i and 9i with PL/SQL package for External Procedures (EXTPROC) allows remote attackers to bypass authentication and execute arbitrary functions by using the TNS Listener to directly connect to the EXTPROC process. | |
| Modificada | Baja (2.1) | 0.49% | — | Oracle Database Server | 6/12/2001 | 16/6/2026 | Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File… | |
| Modificada | Alta (7.2) | 2.1% | 💥 Exploit | Oracle Database Server | 6/12/2001 | 16/6/2026 | Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable, aka the "Oracle Trace Collection Security Vulnerability." | |
| Modificada | Media (4.6) | 0.56% | — | Oracle Database Server | 6/12/2001 | 16/6/2026 | Vulnerabilidad en Oracle Label Security en Oracle 8.1.7 y 9.0.1 cuando se usan la funcionalidad de auditar, SET_LABEL o SQL*Predicate, permite a usuarios locales ganar privilegios adicionales. | |
| Modificada | Media (4.6) | 1.7% | 💥 Exploit | Oracle Database Server | 30/11/2001 | 16/6/2026 | Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable. | |
| Modificada | Media (4.6) | 0.56% | — | Oracle Database Server | 29/11/2001 | 16/6/2026 | dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a malicious version of dbsnmp. | |
| Modificada | Alta (10) | 5.7% | — | Tooltalk Database Server | 30/10/2001 | 16/6/2026 | Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. | |
| Modificada | Alta (7.2) | 2.0% | — | Oracle Database Server | 31/8/2001 | 16/6/2026 | dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs. | |
| Modificada | Baja (2.1) | 0.58% | — | Oracle Database Server | 31/8/2001 | 16/6/2026 | oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable. | |
| Modificada | Media (5) | 2.1% | — | Oracle Database ServerOracle8i | 21/7/2001 | 16/6/2026 | Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value. | |
| Modificada | Media (5) | 1.6% | — | IBM DB2 Universal Database | 11/7/2001 | 16/6/2026 | IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789. | |
| Modificada | Media (5) | 2.8% | — | Oracle Database Server | 12/3/2001 | 16/6/2026 | Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | IBM DB2 Universal Database | 16/2/2001 | 16/6/2026 | IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the database. | |
| Modificada | Baja (2.1) | 1.2% | 💥 Exploit | IBM DB2 Universal Database | 16/2/2001 | 16/6/2026 | IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query. | |
| Modificada | Alta (7.5) | 1.6% | — | Pccs-linux Mysqldatabase Admin Tool | 20/10/2000 | 16/6/2026 | PCCS MySQLDatabase Admin Tool Manager 1.2.4 and earlier installs the file dbconnect.inc within the web root, which allows remote attackers to obtain sensitive information such as the administrative password. | |
| Modificada | Media (4.6) | 1.1% | 💥 Exploit | Oracle Database ServerOracle8i | 16/8/1999 | 16/6/2026 | dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variable, which dbsnmp uses to find the nmiconf.tcl script. | |
| Modificada | Media (4.6) | 1.9% | — | Oracle Database Assistant | 4/3/1999 | 16/6/2026 | Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file. |