Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1340 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.8%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.
ModificadaMedia (5)1.2%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.
ModificadaMedia (4.3)3.9%💥 ExploitCitrix Metaframe31/12/200316/6/2026
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter.
ModificadaMedia (4.3)0.66%—Citrix Access EssentialsCitrix Metaframe Presentation ServerCitrix Presentation Server31/12/200216/6/2026
Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an…
ModificadaMedia (5)2.0%—Novell Emframe29/11/200216/6/2026
Desbordamiento de búfer en Novell iManager (eMFrame) anteriores a 1.5 permite a atacantes remotos causar una denegación de servicio mediante una petición de autenticación con un atributo de Nombre Distinguido (DN) largo.
ModificadaAlta (7.5)3.3%—IBM Tivoli Management Framework4/10/200216/6/2026
Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
ModificadaAlta (7.5)3.3%—IBM Tivoli Management Framework4/10/200216/6/2026
Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
ModificadaMedia (5)2.0%—Novell Emframe4/10/200216/6/2026
Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name.
ModificadaAlta (10)24%—Microsoft .net Framework26/7/200216/6/2026
Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.
ModificadaMedia (5)28%—Microsoft .net Framework26/7/200216/6/2026
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.
ModificadaMedia (5)1.7%—Citrix Metaframe6/12/200116/6/2026
Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server.
ModificadaAlta (7.5)1.4%—Citrix Metaframe21/11/200116/6/2026
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).
ModificadaAlta (9)2.1%—IBM Tivoli Management Framework31/12/200023/9/2026
La interfaz HTTP del Framework de Cliente Ligero de Tivoli (LCF) en IBM Tivoli Management Framework 3.7.1 establece http_disable en cero en el momento de la instalación, lo que permite a usuarios remotos autenticados eludir los permisos de archivo en los archivos de datos de configuración de Tivoli Endpoint mediante…
ModificadaAlta (10)2.3%💥 ExploitCitrix MetaframeCitrix Winframe29/3/200016/6/2026
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
ModificadaBaja (2.1)0.61%—Adobe Framemaker14/8/199616/6/2026
fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access.