Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 6.6% | — | Sophos Anti-virusSophos Anti-virus7.6.3 | 6/8/2009 | 16/6/2026 | Sophos Anti-Virus for Windows before 7.6.3, Anti-Virus for Windows NT/9x before 4.7.18, Anti-Virus for OS X before 4.9.18, Anti-Virus for Linux before 6.4.5, Anti-Virus for UNIX before 7.0.5, Anti-Virus for Unix and Netware before 4.37.0, Sophos EM Library, and Sophos small business solutions, when CAB archive… | |
| Modificada | Media (5) | 2.5% | — | Kaspersky Anti-virusKaspersky Internet Security | 30/7/2009 | 16/6/2026 | Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script." | |
| Modificada | Alta (10) | 3.4% | — | AVG Anti-virus | 22/5/2009 | 16/6/2026 | The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive. | |
| Modificada | Media (6.8) | 2.2% | — | F-secure Anti-virusF-secure Client SecurityF-secure Home Server SecurityF-secure Internet Gatekeeper+2 | 22/5/2009 | 16/6/2026 | Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others;… | |
| Modificada | Media (4.3) | 3.4% | — | AVG Anti-virus | 7/4/2009 | 16/6/2026 | AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption. | |
| Modificada | Alta (7.2) | 0.96% | 💥 Exploit | Kaspersky LAB Kaspersky Anti-virus | 10/2/2009 | 16/6/2026 | Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call. | |
| Modificada | Alta (7.6) | 5.5% | — | F-secure Anti-virusF-secure Anti-virus FOR Citrix ServersF-secure Anti-virus FOR Microsoft ExchangeF-secure Anti-virus FOR Mimesweeper+13 | 6/2/2009 | 16/6/2026 | Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, when configured to scan inside compressed archives, allows remote attackers to execute arbitrary code via a crafted RPM compressed archive file, which triggers a buffer… | |
| Modificada | Alta (10) | 4.3% | — | Broadcom Anti-spywareBroadcom Anti-spyware FOR THE EnterpriseBroadcom Anti-virusBroadcom Anti-virus FOR THE Enterprise+15 | 28/1/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a… | |
| Modificada | Alta (9.3) | 7.6% | — | Sophos Anti-virus | 12/12/2008 | 16/6/2026 | Sophos Anti-Virus 4.33.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a… | |
| Modificada | Alta (9.3) | 3.0% | — | Drweb Anti-virus | 12/12/2008 | 16/6/2026 | DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated… | |
| Modificada | Media (4.3) | 8.2% | 💥 Exploit | Clam Anti-virus Clamav | 3/12/2008 | 16/6/2026 | Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions. | |
| Modificada | Alta (9.3) | 8.3% | — | Clam Anti-virus Clamav | 13/11/2008 | 16/6/2026 | Off-by-one error in the get_unicode_name function (libclamav/vba_extract.c) in Clam Anti-Virus (ClamAV) before 0.94.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted VBA project file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 3.4% | — | Clam Anti-virus Clamav | 4/9/2008 | 16/6/2026 | libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an "invalid memory access." | |
| Modificada | Media (5) | 4.7% | — | Clam Anti-virus Clamav | 18/7/2008 | 16/6/2026 | libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-bounds memory access. NOTE: this issue exists because of an incomplete fix for CVE-2008-2713. | |
| Modificada | Media (5) | 5.1% | — | Sophos Es1000Sophos Es4000Sophos Anti-virusSophos Puremessage Anti-virus | 15/7/2008 | 16/6/2026 | Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments. | |
| Modificada | Media (5) | 4.7% | — | Clam Anti-virus Clamav | 16/6/2008 | 16/6/2026 | libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read. | |
| Modificada | Alta (7.2) | 0.37% | — | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security | 5/6/2008 | 16/6/2026 | Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call. | |
| Modificada | Media (6.9) | 0.62% | — | Sophos Anti-virus | 30/4/2008 | 16/6/2026 | Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System… | |
| Modificada | Media (4.3) | 3.5% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | The rfc2231 function in message.c in libclamav in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via a crafted message that produces a string that is not null terminated, which triggers a buffer over-read. | |
| Modificada | Media (5) | 4.8% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | libclamunrar in ClamAV before 0.93 allows remote attackers to cause a denial of service (crash) via crafted RAR files that trigger "memory problems," as demonstrated by the PROTOS GENOME test suite for Archive Formats. | |
| Modificada | Media (4.3) | 4.4% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | ClamAV before 0.93 allows remote attackers to cause a denial of service (CPU consumption) via a crafted ARJ archive, as demonstrated by the PROTOS GENOME test suite for Archive Formats. | |
| Modificada | Media (5) | 4.0% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | ClamAV before 0.93 allows remote attackers to bypass the scanning enging via a RAR file with an invalid version number, which cannot be parsed by ClamAV but can be extracted by Winrar. | |
| Modificada | Alta (7.5) | 9.0% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | Heap-based buffer overflow in spin.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted PeSpin packed PE binary with a modified length value. | |
| Modificada | Alta (7.5) | 8.6% | — | Clam Anti-virus Clamav | 16/4/2008 | 16/6/2026 | Heap-based buffer overflow in pe.c in libclamav in ClamAV 0.92.1 allows remote attackers to execute arbitrary code via a crafted WWPack compressed PE binary. | |
| Modificada | Alta (10) | 11% | — | Clam Anti-virus Clamav | 14/4/2008 | 16/6/2026 | Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file. |