Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.2) | 0.39% | — | Symantec Norton APP Lock | 24/1/2019 | 17/6/2026 | Norton App Lock prior to 1.4.0.445 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access. | |
| Modificada | Media (6.1) | 0.91% | — | Symantec Norton Password Manager | 6/12/2018 | 17/6/2026 | Norton Password Manager for Android (formerly Norton Identity Safe) may be susceptible to a cross site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to… | |
| Modificada | Alta (7.8) | 1.1% | — | Symantec Endpoint Protection | 29/11/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14.2 MP1 may be susceptible to a DLL Preloading vulnerability, which in this case is an issue that can occur when an application being installed unintentionally loads a DLL provided by a potential attacker. Note that this particular type of exploit only manifests at install time;… | |
| Modificada | Media (6.8) | 0.52% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Alta (7.8) | 0.40% | — | Symantec Endpoint ProtectionSymantec Endpoint Protection CloudSymantec Norton Antivirus | 29/11/2018 | 17/6/2026 | Norton prior to 22.15; Symantec Endpoint Protection (SEP) prior to 12.1.7454.7000 & 14.2; Symantec Endpoint Protection Small Business Edition (SEP SBE) prior to NIS-22.15.1.8 & SEP-12.1.7454.7000; and Symantec Endpoint Protection Cloud (SEP Cloud) prior to 22.15.1 may be susceptible to an AV bypass issue, which is a… | |
| Modificada | Media (6.1) | 1.00% | — | Symantec Security Analytics | 27/11/2018 | 17/6/2026 | The Symantec Security Analytics (SA) 7.x prior to 7.3.4 Web UI is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker with knowledge of the SA web UI hostname or IP address can craft a malicious URL for the SA web UI and target SA web UI users with phishing attacks or other social… | |
| Modificada | Media (6.1) | 1.00% | — | Symantec WEB Isolation | 22/10/2018 | 17/6/2026 | Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code… | |
| Modificada | Alta (8.8) | 0.77% | — | Symantec Messaging Gateway | 19/9/2018 | 17/6/2026 | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system… | |
| Modificada | Crítica (9.8) | 3.0% | — | Symantec Messaging Gateway | 19/9/2018 | 17/6/2026 | The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network. | |
| Modificada | Media (5.9) | 1.1% | — | Symantec Norton Password Manager | 29/8/2018 | 17/6/2026 | The Norton Identity Safe product prior to 5.3.0.976 may be susceptible to a privilege escalation issue via a hard coded IV, which is a type of vulnerability that can potentially increase the likelihood of encrypted data being recovered without adequate credentials. | |
| Modificada | Alta (7.8) | 1.6% | — | Symantec Norton Power EraserSymantec Symdiag | 22/8/2018 | 17/6/2026 | Norton Power Eraser (prior to 5.3.0.24) and SymDiag (prior to 2.1.242) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is… | |
| Modificada | Media (6) | 0.39% | — | Symantec Norton Utilities | 22/8/2018 | 17/6/2026 | Norton Utilities (prior to 16.0.3.44) may be susceptible to a DLL Preloading vulnerability, which is a type of issue that can occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a… | |
| Modificada | Alta (7.5) | 1.8% | — | Symantec Encryption Management Server | 20/8/2018 | 17/6/2026 | The Symantec Encryption Management Server (SEMS) product, prior to version 3.4.2 MP1, may be susceptible to a denial of service (DoS) exploit. A DoS attack is a type of attack whereby the perpetrator attempts to make a particular machine or network resource unavailable to its intended users by temporarily or… | |
| Modificada | Alta (8) | 1.1% | — | Symantec Inventory | 25/7/2018 | 17/6/2026 | The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. | |
| Modificada | Media (5.9) | 4.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+16 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise… | |
| Modificada | Alta (8.3) | 3.2% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Baja (3.7) | 4.4% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+22 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (8.3) | 1.9% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Alta (8.3) | 2.6% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (4.3) | 3.1% | — | Oracle JDKOracle JREHP XP7 Command ViewRedhat Satellite+16 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9) | 2.1% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+11 | 18/7/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in… | |
| Modificada | Media (6.2) | 0.39% | — | Symantec Norton APP Lock | 16/7/2018 | 17/6/2026 | Norton App Lock prior to v1.3.0.332 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access. | |
| Modificada | Alta (8.8) | 1.9% | — | Symantec Endpoint Protection | 20/6/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels. | |
| Modificada | Media (5.3) | 1.1% | — | Symantec Endpoint Protection | 20/6/2018 | 17/6/2026 | Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events. | |
| Modificada | Media (6.2) | 0.39% | — | Symantec Norton APP Lock | 13/6/2018 | 17/6/2026 | Norton App Lock prior to version 1.3.0.329 can be susceptible to a bypass exploit. In this type of circumstance, the exploit can allow the user to circumvent the app to prevent it from locking the device, thereby allowing the individual to gain device access. |