Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
140 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.2% | — | Altiris Deployment Solution | 6/11/2007 | 16/6/2026 | Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (6.9) | 0.33% | — | Symantec Altiris Deployment Solution | 18/10/2007 | 16/6/2026 | Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information.… | |
| Modificada | Alta (7.2) | 0.35% | — | Symantec Altiris Deployment Solution | 16/8/2007 | 16/6/2026 | Aclient in Symantec Altiris Deployment Solution 6 before 6.8 SP2 (6.8.378) allows local users to gain local System privileges via the Log File Viewer. | |
| Modificada | Media (6.8) | 1.5% | — | Madirish Webmail | 6/6/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown;… | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Madirish Webmail | 22/5/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Brian Wotring Osiris | 31/7/2006 | 16/6/2026 | Format string vulnerability in Brian Wotring Osiris before 4.2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified attack vectors related to the logging functions. | |
| Modificada | Alta (7.5) | 1.9% | 💥 Exploit | Lawrence Osiris DB Esession | 19/2/2006 | 16/6/2026 | SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID. | |
| Modificada | Media (5.1) | 1.7% | — | Broadcom Etrust AntivirusBroadcom Etrust Antivirus Iris Engine | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of (1) eTrust-Iris and (2) eTrust-Vet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip,… | |
| Modificada | Media (4.6) | 0.92% | 💥 Exploit | Altiris Client ServiceAltiris Deployment Solution | 16/5/2005 | 16/6/2026 | The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the… | |
| Modificada | Alta (7.2) | 0.45% | — | Symantec Altiris Client ServiceAI | 31/12/2004 | 16/6/2026 | The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590. | |
| Modificada | Alta (10) | 2.6% | — | Altiris Deployment Server Extension FOR IBM Director | 31/12/2004 | 16/6/2026 | AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access. | |
| Modificada | Alta (7.2) | 0.34% | — | Altiris Carbon Copy | 21/10/2004 | 16/6/2026 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). | |
| Modificada | Alta (7.5) | 1.8% | — | SGI Irisconsole | 16/5/2002 | 16/6/2026 | IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges. | |
| Modificada | Baja (2.6) | 2.7% | 💥 Exploit | Eeye Digital Security Iris | 26/3/2001 | 16/6/2026 | eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Eeye Digital Security IrisSpynet Capturenet | 20/10/2000 | 16/6/2026 | eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections. |