Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
141 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 24% | — | Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function. | |
| Modificada | Media (5) | 16% | — | Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEAvaya Definity ONE Media ServerAvaya S8100+4 | 6/8/2004 | 16/6/2026 | Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share. | |
| Modificada | Media (6.8) | 45% | 💥 Exploit | Avaya Converged Communications ServerRedhat Fedora CoreTrustix Secure LinuxAvaya Integrated Management+4 | 27/7/2004 | 16/6/2026 | The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the… | |
| Modificada | Media (5.1) | 55% | 💥 Exploit | OpenpkgAvaya Converged Communications ServerDebian LinuxHp-ux+2 | 27/7/2004 | 16/6/2026 | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor… | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | |
| Modificada | Alta (7.2) | 1.2% | 💥 Exploit | Hp-uxAvaya Predictive Dialer System | 31/12/2003 | 16/6/2026 | Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command line argument. | |
| Modificada | Alta (7.5) | 3.3% | — | Avaya Cajun P550Avaya Cajun P550rAvaya Cajun P580Avaya Cajun P880+1 | 28/10/2002 | 16/6/2026 | Avaya Cajun switches P880, P882, P580, and P550R 5.2.14 and earlier contain undocumented accounts (1) manuf and (2) diag with default passwords, which allows remote attackers to gain privileges. | |
| Modificada | Alta (7.5) | 1.5% | — | Avaya Cajun M770-atmAvaya Cajun P130Avaya Cajun P330 | 8/7/2002 | 16/6/2026 | An undocumented SNMP read/write community string ('NoGaH$@!') in Avaya P330, P130, and M770-ATM Cajun products allows remote attackers to gain administrative privileges. | |
| Modificada | Media (4.6) | 0.47% | — | Avaya Libsafe | 22/4/2002 | 16/6/2026 | The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not verified by libsafe. | |
| Modificada | Media (4.6) | 0.47% | — | Avaya Libsafe | 22/4/2002 | 16/6/2026 | libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxAvaya CvlanAvaya Integrated Management SuitAvaya Interactive Response+3 | 31/12/2001 | 16/6/2026 | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. | |
| Modificada | Alta (10) | 1.8% | — | Avaya Argent Office | 7/8/2001 | 16/6/2026 | Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot. | |
| Modificada | Media (5) | 1.2% | — | Avaya Argent Office | 7/8/2001 | 16/6/2026 | Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Avaya Argent Office | 7/8/2001 | 16/6/2026 | Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload. | |
| Modificada | Alta (7.5) | 1.6% | — | Avaya Argent Office | 7/8/2001 | 16/6/2026 | Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string. |