Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.2%—Altiris Deployment Solution6/11/200716/6/2026
Directory traversal vulnerability in the tftp/mftp daemon in the PXE server component (pxemtftp.exe) in Symantec Altiris Deployment Solution 6.x before 6.8.380.0 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (6.9)0.33%—Symantec Altiris Deployment Solution18/10/200716/6/2026
Unspecified vulnerability in Symantec Altiris Deployment Solution allows attackers to obtain authentication credentials via unknown vectors, aka "Authentication Credentials Information Leakage in Altiris Deployment Solution." NOTE: this description is based on a vague pre-advisory with no actionable information.…
ModificadaAlta (7.2)0.35%—Symantec Altiris Deployment Solution16/8/200716/6/2026
Aclient in Symantec Altiris Deployment Solution 6 before 6.8 SP2 (6.8.378) allows local users to gain local System privileges via the Log File Viewer.
ModificadaMedia (6.8)1.5%—Madirish Webmail6/6/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Madirish Webmail 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter to (1) calendar.php, (2) compose.php, and (3) index.php, different vectors than CVE-2007-2826. NOTE: the provenance of this information is unknown;…
ModificadaAlta (7.5)3.3%💥 ExploitMadirish Webmail22/5/200716/6/2026
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[basedir] parameter.
ModificadaAlta (7.5)3.2%—Brian Wotring Osiris31/7/200616/6/2026
Format string vulnerability in Brian Wotring Osiris before 4.2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified attack vectors related to the logging functions.
ModificadaAlta (7.5)1.9%💥 ExploitLawrence Osiris DB Esession19/2/200616/6/2026
SQL injection vulnerability in deleteSession() in DB_eSession library 1.0.2 and earlier, as used in multiple products, allows remote attackers to execute arbitrary SQL commands via the $_sess_id_set variable, which is usually derived from PHPSESSID.
ModificadaMedia (5.1)1.7%—Broadcom Etrust AntivirusBroadcom Etrust Antivirus Iris Engine14/10/200516/6/2026
Multiple interpretation error in unspecified versions of (1) eTrust-Iris and (2) eTrust-Vet Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip,…
ModificadaMedia (4.6)0.92%💥 ExploitAltiris Client ServiceAltiris Deployment Solution16/5/200516/6/2026
The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the…
ModificadaAlta (7.2)0.45%—Symantec Altiris Client ServiceAI31/12/200416/6/2026
The Altiris Client Service for Windows 5.6 SP1 Hotfix E (5.6.181) allows local users to execute arbitrary commands by opening the AClient tray icon and using the View Log File option, a different vulnerability than CVE-2005-1590.
ModificadaAlta (10)2.6%—Altiris Deployment Server Extension FOR IBM Director31/12/200416/6/2026
AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access.
ModificadaAlta (7.2)0.34%—Altiris Carbon Copy21/10/200416/6/2026
Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).
ModificadaAlta (7.5)1.8%—SGI Irisconsole16/5/200216/6/2026
IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.
ModificadaBaja (2.6)2.7%💥 ExploitEeye Digital Security Iris26/3/200116/6/2026
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.
ModificadaMedia (5)2.5%💥 ExploitEeye Digital Security IrisSpynet Capturenet20/10/200016/6/2026
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.
Orbitaley — Vulnerabilidades