Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Advantage Century Telecommunication P202s | 22/1/2006 | 16/6/2026 | Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allow remote attackers to provide false time information, block access to time information, or conduct other attacks. | |
| Modificada | Alta (7.5) | 1.6% | — | Advantage Century Telecommunication P202s | 22/1/2006 | 16/6/2026 | Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtain sensitive information, such as memory contents and internal operating-system data, by directly accessing the VxWorks WDB remote debugging… | |
| Modificada | Alta (7.5) | 2.6% | — | SUN Java Communications Services Delegated Administrator | 7/12/2005 | 16/6/2026 | Unspecified vulnerability in System Communications Services 6 Delegated Administrator 2005Q1 in Sun Java System Messaging Server 2005Q1 allows remote attackers to obtain the Top-Level Administrator (TLA) default password via unknown vectors, possibly involving configure_toplevel_admin.ldif. | |
| Modificada | Alta (7.8) | 1.5% | — | Macromedia Flash Communication Server | 29/11/2005 | 16/6/2026 | Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.8) | 1.7% | — | Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI | 29/11/2005 | 16/6/2026 | Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Media (5) | 2.3% | — | SUN Java System Communications Express | 3/11/2005 | 16/6/2026 | Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method. | |
| Modificada | Media (4.6) | 1.4% | — | MRV Communications In-reach Lx-8000sAIMRV Communications In-reach Lx-4000sAIMRV Communications In-reach Lx-1000sAI | 20/7/2005 | 16/6/2026 | MRV Communications In-Reach LX-8000S, LX-4000S, y LX-1000S 3.5.0 cuando usa autenficación por clave pública SSH, no restringe adecuadamente el acceso a los puertos, lo que permite que usuarios autenficados remotos accedan a las consolas de otros usuarios. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Baja (2.1) | 0.40% | — | KDE DcopserverKDE Desktop Communication Protocol Daemon | 2/5/2005 | 16/6/2026 | Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process." | |
| Modificada | Media (6.2) | 2.9% | 💥 Exploit | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+16 | 14/4/2005 | 16/6/2026 | Condición de carrera en las llamadas de funciones (1) load_elf_library y (2) binfmt_aout de uselib de los kernel de Linux 2.4 a 2.429-rc2 y 2.6 a 2.6.10 permite a usuarios locales ejecutar código de su elección manipulando el descriptor WMA. | |
| Modificada | Baja (2.1) | 0.51% | — | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+11 | 14/4/2005 | 16/6/2026 | El soporte de ELF de 64 bits en los kernel de Linux 2.6 anteriores a 2.6.10 en arquitecturas de 64 bits no verifica adecuadamente solapamientos en asignaciones de memoria VMA (virtual memory address), lo que permite a usuarios locales causar una denegación de servicio (caída del sistema) o ejecutar código de su… | |
| Modificada | Media (5) | 1.6% | — | Mitel 3300 Integrated Communication Platform | 28/2/2005 | 16/6/2026 | The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum. | |
| Modificada | Alta (7.8) | 2.3% | — | First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate | 31/12/2004 | 16/6/2026 | Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test… | |
| Modificada | Media (4.3) | 4.1% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in register.asp in Snitz Forums 2000 3.4.04 and earlier allows remote attackers to inject arbitrary web script or HTML via javascript events in the Email parameter. | |
| Modificada | Media (5) | 59% | 💥 Exploit | Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+15 | 23/12/2004 | 16/6/2026 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number… | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (7.5) | 3.6% | — | Widcomm Bluetooth Communication SoftwareWidcomm Btstackserver | 20/10/2004 | 16/6/2026 | Desbordamiento de búfer en WIDCOMM Bluetooth Connectivity Software, usado en productos como BTStackServer 1.3.2.7 y 1.4.2.10, Windows XP y Windows 98 con mochilas Bluetooth MSI, y HP IPAQ 5450 con WinCE 3.0, permite a atacantes remotos ejecutar código de su elección mediante ciertas peticiones de servicio. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 16/9/2004 | 16/6/2026 | CRLF injection vulnerability in down.asp for Snitz Forums 2000 3.4.04 allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the location parameter. | |
| Modificada | Alta (7.2) | 0.42% | — | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Múltiples vulnerabilidades desconocidas en el kernel de Linux 2.4 y 2.6 permiten a usuarios locales ganar privilegios o acceder a memoria del kernel, como se ha encontrado mediante la herramienta de comprobación de código fuente "Sparse". | |
| Modificada | Media (6.4) | 85% | 💥 Exploit | Avaya Converged Communications ServerGentoo LinuxTrustix Secure LinuxApache Http Server+4 | 6/8/2004 | 16/6/2026 | La función ap_get_mime_headers_core de Apache httpd 2.0.49 permite a atacantes remotos causar una denegación de servicio (consumición de memoria) y posiblemente un error de entero sin signo que conduce a un desbordamiento de búfer basado en el montón en en sistemas de 64 bits, mediante líneas de cabecera largas con… | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | El kernel de Linux 2.4.2x y 2.6.x para x86 permite a usuarios locales causar una denegación de servicio (caída del sistema), posiblemente mediante un bucle infinito que dispara un manejador de señal con una cierta secuencia de instrucciones fsave y fstor, originalmente demostrado con el programa "crash.c". | |
| Modificada | Media (5.1) | 55% | 💥 Exploit | OpenpkgAvaya Converged Communications ServerDebian LinuxHp-ux+2 | 27/7/2004 | 16/6/2026 | La funcionalidad memory_limit de PHP 4.x a 4.3.7 y 5.x a 5.0.0RC3, bajo ciertas condiciones, como cuando register_globals está habilitado, permite a atacantes remotos ejecutar código de su elección disparando un aborto por memory_limit de la función zend_hash_init y sobrescribiendo un puntero de destructor de… |