Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

251 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)2.2%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+415/2/200816/6/2026
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
ModificadaAlta (10)7.9%—Clam Anti-virus Clamav12/2/200816/6/2026
Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
ModificadaMedia (5)2.3%—Clam Anti-virus Clamav31/12/200716/6/2026
ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.
ModificadaBaja (2.1)0.41%—Clam Anti-virus Clamav31/12/200716/6/2026
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.
ModificadaAlta (10)2.8%—Clam Anti-virus Clamav31/12/200716/6/2026
Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.
ModificadaMedia (6.8)4.2%—Clam Anti-virus Clamav20/12/200716/6/2026
Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.
ModificadaAlta (7.5)18%💥 ExploitClam Anti-virus Clamav20/12/200716/6/2026
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.
ModificadaAlta (9.3)8.1%💥 ExploitBitdefender Online Anti-virus Scanner30/11/200716/6/2026
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper…
ModificadaAlta (7.5)2.6%—Clam Anti-virus Clamav20/11/200716/6/2026
Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has…
ModificadaBaja (1.9)0.30%—F-secure Anti-virus1/10/200716/6/2026
F-Secure Anti-Virus for Windows Servers 7.0 64-bit edition allows local users to bypass virus scanning by using the system32 directory to store a crafted (1) archive or (2) packed executable. NOTE: in many environments, this does not cross privilege boundaries because any process able to write to system32 could also…
ModificadaBaja (2.1)0.44%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security26/9/200716/6/2026
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4)…
ModificadaMedia (5)5.7%—Sophos Scanning EngineSophos Anti-virus10/9/200716/6/2026
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
ModificadaMedia (4.3)4.8%—Sophos Anti-virus10/9/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in…
ModificadaAlta (7.2)0.89%💥 ExploitMicroworld Technologies Escan Anti-virusMicroworld Technologies Escan Internet SecurityMicroworld Technologies Escan Virus Control31/8/200716/6/2026
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
ModificadaMedia (6.8)7.3%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows…
ModificadaAlta (7.8)5.5%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
ModificadaAlta (7.6)84%💥 ExploitClam Anti-virus Clamav28/8/200716/6/2026
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
ModificadaMedia (4.3)2.0%—Clam Anti-virus ClamavKolab Server23/8/200716/6/2026
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI,…
ModificadaMedia (4.3)3.6%—Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+1926/7/200716/6/2026
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
ModificadaMedia (5)1.9%—Kaspersky LAB Kaspersky Anti-virus 5.5 FOR Check Point Firewall-19/7/200716/6/2026
Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.
ModificadaAlta (9.3)14%—Broadcom Alert Notification ServerBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupCA Anti-virus FOR THE Enterprise+418/7/200716/6/2026
Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers…
ModificadaMedia (4.3)7.7%💥 ExploitClam Anti-virus Clamav12/7/200716/6/2026
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.
ModificadaAlta (9.3)3.7%—F-secure Anti-virusF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server SecurityF-secure Internet Security+220/6/200716/6/2026
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
ModificadaMedia (5)1.4%—Clam Anti-virus Clamav7/6/200716/6/2026
Unspecified vulnerability in libclamav/phishcheck.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1, when running on Solaris, allows remote attackers to cause a denial of service (hang) via unknown vectors related to the isURL function and regular expressions.
ModificadaBaja (2.1)0.36%—Clam Anti-virus Clamav7/6/200716/6/2026
libclamav/others.c in ClamAV before 0.90.3 and 0.91 before 0.91rc1 uses insecure permissions for temporary files that are created by the cli_gentempstream function in clamd/clamdscan, which might allow local users to read sensitive files.
Orbitaley — Vulnerabilidades