Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1340 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.8% | — | Citrix Metaframe ClientCitrix Program Neighborhood Agent | 26/4/2004 | 16/6/2026 | Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element. | |
| Modificada | Media (5) | 1.2% | — | Citrix Metaframe ClientCitrix Program Neighborhood Agent | 26/4/2004 | 16/6/2026 | Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Citrix Metaframe | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to inject arbitrary web script or HTML via the NFuse_Message parameter. | |
| Modificada | Media (4.3) | 0.66% | — | Citrix Access EssentialsCitrix Metaframe Presentation ServerCitrix Presentation Server | 31/12/2002 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs, as authenticated users via the InitialProgram key in an… | |
| Modificada | Media (5) | 2.0% | — | Novell Emframe | 29/11/2002 | 16/6/2026 | Desbordamiento de búfer en Novell iManager (eMFrame) anteriores a 1.5 permite a atacantes remotos causar una denegación de servicio mediante una petición de autenticación con un atributo de Nombre Distinguido (DN) largo. | |
| Modificada | Alta (7.5) | 3.3% | — | IBM Tivoli Management Framework | 4/10/2002 | 16/6/2026 | Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 3.3% | — | IBM Tivoli Management Framework | 4/10/2002 | 16/6/2026 | Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request. | |
| Modificada | Media (5) | 2.0% | — | Novell Emframe | 4/10/2002 | 16/6/2026 | Buffer overflow in Novell iManager (eMFrame 1.2.1) allows remote attackers to cause a denial of service (crash) via a long user name. | |
| Modificada | Alta (10) | 24% | — | Microsoft .net Framework | 26/7/2002 | 16/6/2026 | Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode. | |
| Modificada | Media (5) | 28% | — | Microsoft .net Framework | 26/7/2002 | 16/6/2026 | orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter. | |
| Modificada | Media (5) | 1.7% | — | Citrix Metaframe | 6/12/2001 | 16/6/2026 | Citrix MetaFrame 1.8 Server with Service Pack 3, and XP Server Service Pack 1 and earlier, allows remote attackers to cause a denial of service (crash) via a large number of incomplete connections to the server. | |
| Modificada | Alta (7.5) | 1.4% | — | Citrix Metaframe | 21/11/2001 | 16/6/2026 | CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT). | |
| Modificada | Alta (9) | 2.1% | — | IBM Tivoli Management Framework | 31/12/2000 | 23/9/2026 | La interfaz HTTP del Framework de Cliente Ligero de Tivoli (LCF) en IBM Tivoli Management Framework 3.7.1 establece http_disable en cero en el momento de la instalación, lo que permite a usuarios remotos autenticados eludir los permisos de archivo en los archivos de datos de configuración de Tivoli Endpoint mediante… | |
| Modificada | Alta (10) | 2.3% | 💥 Exploit | Citrix MetaframeCitrix Winframe | 29/3/2000 | 16/6/2026 | The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication. | |
| Modificada | Baja (2.1) | 0.61% | — | Adobe Framemaker | 14/8/1996 | 16/6/2026 | fm_fls license server for Adobe Framemaker allows local users to overwrite arbitrary files and gain root access. |