Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2751▼ 38 respecto a la semana anterior
Críticas / altas1262▼ 270 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 209 respecto a la semana anterior
–

1237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.8%—Symantec Liveupdate25/6/200216/6/2026
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.
ModificadaBaja (1.2)0.32%—Oliver Rauch Xsane15/1/200216/6/2026
xSANE 0.81 y anteriores permiten a usuarios locales modificar ficheros de otros usuarios de xSANE mediante un ataque de enlaces simbólicos (symlink) en ficheros temporales.
ModificadaMedia (5)2.6%—Symantec Liveupdate5/10/200116/6/2026
Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.
ModificadaCrítica (9.8)2.5%—Symantec Liveupdate5/10/200116/6/2026
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.
ModificadaMedia (4.6)0.38%—Symantec Liveupdate14/8/200116/6/2026
Symantec LiveUpdate 1.5 stores proxy passwords in cleartext in a registry key, which could allow local users to obtain the passwords.
ModificadaAlta (7.5)4.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.6)6.4%—Oliver Debon Flash12/3/200116/6/2026
Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.
ModificadaAlta (7.5)3.7%💥 ExploitMediahouse Software Statistics Server Livestats20/10/200016/6/2026
Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.
ModificadaAlta (7.5)2.0%—Intelligent Vending Systems Intellivend1/2/200016/6/2026
The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.
ModificadaAlta (7.6)3.5%💥 ExploitVdonet Vdolive Player13/12/199916/6/2026
Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo file.
ModificadaMedia (5)2.6%💥 ExploitPacific Software URL Live28/10/199916/6/2026
URL Live! web server allows remote attackers to read arbitrary files via a .. (dot dot) attack.