Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.99% | 💥 Exploit | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | AVG Anti-Virus plus Firewall 7.5.431 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Sygate Personal Firewall 5.6.2808 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Alta (7.2) | 0.33% | — | AVG Antivirus Plus FirewallComodo Personal FirewallFilseclab Personal FirewallInfoprocess Antihook+2 | 18/12/2006 | 16/6/2026 | Soft4Ever Look 'n' Stop (LnS) 2.05p2 before 20061215 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | |
| Modificada | Media (4) | 2.4% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 6/11/2006 | 16/6/2026 | XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus PersonalKaspersky LAB Kaspersky Anti-virus Personal PROKaspersky LAB Kaspersky Internet Security | 20/10/2006 | 16/6/2026 | The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code via crafted Irp structure with invalid addresses in the… | |
| Modificada | Media (5) | 1.8% | — | Mcafee Internet Security SuiteMcafee Network AgentMcafee Personal Firewall PlusMcafee Virusscan | 20/10/2006 | 16/6/2026 | McAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus, and VirusScan, allows remote attackers to cause a denial of service (agent crash) via a long packet, possibly because of an invalid string position field value. NOTE:… | |
| Modificada | Media (5) | 1.6% | — | Kerio Personal Firewall | 5/10/2006 | 16/6/2026 | The (1) fwdrv.sys and (2) khips.sys drivers in Sunbelt Kerio Personal Firewall 4.3.268 and earlier do not validate arguments passed through to SSDT functions, including NtCreateFile, NtDeleteFile, NtLoadDriver, NtMapViewOfSection, NtOpenFile, and NtSetInformationFile, which allows local users to cause a denial of… | |
| Modificada | Media (4.9) | 1.3% | 💥 Exploit | Symantec Client SecuritySymantec Host IDSSymantec Norton AntivirusSymantec Norton Internet Security+3 | 19/9/2006 | 16/6/2026 | The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5… | |
| Modificada | Media (4.6) | 0.33% | — | Avira Antivir Personal | 7/9/2006 | 16/6/2026 | The start update window in update.exe in Avira AntiVir PersonalEdition Classic 7.0 build 151 allows local users to gain system privileges via a "Shatter" style attack on the (1) IParam parameter, and the (2) PBM_GETRANGE and (3) PBM_SETRANGE messages in an unspecified progress bar. NOTE: some details are obtained from… | |
| Modificada | Baja (3.6) | 0.35% | — | Symantec Norton Personal Firewall | 21/8/2006 | 16/6/2026 | Symantec Norton Personal Firewall 2006 9.1.0.33, and possibly earlier, does not properly protect Norton registry keys, which allows local users to provide Trojan horse libraries to Norton by using RegSaveKey and RegRestoreKey to modify HKLM\SOFTWARE\Symantec\CCPD\SuiteOwners, as demonstrated using NISProd.dll. NOTE:… | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands… | |
| Modificada | Baja (2.1) | 0.71% | 💥 Exploit | Kerio Personal Firewall | 24/7/2006 | 16/6/2026 | kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread. | |
| Modificada | Baja (2.1) | 0.40% | — | Symantec Norton Personal Firewall | 21/7/2006 | 16/6/2026 | Norton Personal Firewall 2006 9.1.0.33 allows local users to cause a denial of service (crash) via certain RegSaveKey, RegRestoreKey and RegDeleteKey operations on the (1) HKLM\SYSTEM\CurrentControlSet\Services\SNDSrvc and (2) HKLM\SYSTEM\CurrentControlSet\Services\SymEvent registry keys. | |
| Modificada | Alta (7.2) | 0.48% | — | Agnitum Outpost FirewallLavasoft Personal FirewallNovell Client Firewall | 21/7/2006 | 16/6/2026 | Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Client Firewall 2.0, does not properly restrict user activities in application windows that run in a LocalSystem context, which allows local users to gain privileges and… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 5/5/2006 | 16/6/2026 | Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the PORT command. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Dxmsoft XM Easy Personal FTP Server | 5/5/2006 | 16/6/2026 | Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username. | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Alta (7.2) | 0.38% | — | Avira Antivir Personal | 19/3/2006 | 16/6/2026 | Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports. | |
| Modificada | Alta (7.2) | 0.34% | — | Starforce Safe N SEC Personal + Anti-spyware | 23/2/2006 | 16/6/2026 | Unquoted Windows search path vulnerability in (1) snsmcon.exe, (2) the autostartup mechanism, and (3) an unspecified installation component in StarForce Safe'n'Sec Personal + Anti-Spyware 2.0 and earlier, and possibly other StarForce Safe'n'Sec products, might allow local users to gain privileges via a malicious… | |
| Modificada | Media (5) | 3.0% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper | 21/1/2006 | 16/6/2026 | Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP… | |
| Modificada | Alta (7.5) | 5.8% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Internet GatekeeperSolutions Based ON F-secure Personal Express | 21/1/2006 | 16/6/2026 | Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Alta (7.5) | 1.3% | — | Almondsoft Almond Personals | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in AlmondSoft Almond Personals 4.05 allows remote attackers to execute arbitrary SQL commands via the id parameter. |