Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
1237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.8% | — | Symantec Liveupdate | 25/6/2002 | 16/6/2026 | Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server. | |
| Modificada | Baja (1.2) | 0.32% | — | Oliver Rauch Xsane | 15/1/2002 | 16/6/2026 | xSANE 0.81 y anteriores permiten a usuarios locales modificar ficheros de otros usuarios de xSANE mediante un ataque de enlaces simbólicos (symlink) en ficheros temporales. | |
| Modificada | Media (5) | 2.6% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site. | |
| Modificada | Crítica (9.8) | 2.5% | — | Symantec Liveupdate | 5/10/2001 | 16/6/2026 | Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site. | |
| Modificada | Media (4.6) | 0.38% | — | Symantec Liveupdate | 14/8/2001 | 16/6/2026 | Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords. | |
| Modificada | Alta (7.5) | 4.3% | — | Critical Path Injoin Directory ServerCritical Path Livecontent Directory | 16/7/2001 | 16/6/2026 | Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite. | |
| Modificada | Alta (7.5) | 5.3% | — | Critical Path Injoin Directory ServerCritical Path Livecontent Directory | 16/7/2001 | 16/6/2026 | Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite. | |
| Modificada | Alta (7.6) | 6.4% | — | Oliver Debon Flash | 12/3/2001 | 16/6/2026 | Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Mediahouse Software Statistics Server Livestats | 20/10/2000 | 16/6/2026 | Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 2.0% | — | Intelligent Vending Systems Intellivend | 1/2/2000 | 16/6/2026 | The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields. | |
| Modificada | Alta (7.6) | 3.5% | 💥 Exploit | Vdonet Vdolive Player | 13/12/1999 | 16/6/2026 | Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Pacific Software URL Live | 28/10/1999 | 16/6/2026 | URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack. |