Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 6.3.3 Hotfix 27 and 7.x before 7.1.1 allow remote attackers to cause a denial of service (Blue Coat appliance integration outage) via a long URL. | |
| Modificada | Media (5) | 1.4% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |
| Modificada | Media (5) | 1.2% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The Remote Filtering component in Websense Web Security and Web Filter before 6.3.3 Hotfix 18 and 7.x before 7.1.1 allows remote attackers to cause a denial of service (daemon exit) via a large volume of traffic. | |
| Modificada | Baja (2.1) | 0.39% | — | Websense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The Remote Filtering component in Websense Web Security and Web Filter before 7.1 Hotfix 66 allows local users to bypass filtering by (1) renaming the WDC.exe file or (2) deleting driver files. | |
| Modificada | Media (4.3) | 1.3% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The Filtering Service in Websense Web Security and Web Filter before 6.3.1 Hotfix 136 and 7.x before 7.1.1 on Windows allows remote attackers to cause a denial of service (filtering outage) via a crafted sequence of characters in a URI. | |
| Modificada | Media (4.3) | 1.5% | — | WebsenseWebsense WEB SecurityWebsense WEB Filter | 23/8/2012 | 16/6/2026 | The ISAPI Filter plug-in in Websense Enterprise, Websense Web Security, and Websense Web Filter 6.3.3 and earlier, when used in conjunction with a Microsoft ISA or Microsoft Forefront TMG server, allows remote attackers to bypass intended filtering and monitoring activities for web traffic via an HTTP Via header. | |
| Modificada | Media (4.3) | 0.94% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 allows connections to TCP port 1812 from arbitrary source IP addresses, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via UTF-7 text to the 404 error page of a… | |
| Modificada | Media (4.3) | 1.1% | — | Websense WEB FilterWebsense WEB Security | 23/8/2012 | 16/6/2026 | The default configuration of Apache Tomcat in Websense Manager in Websense Web Security 7.0 and Web Filter 7.0 enables weak SSL ciphers in conf/server.xml, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and then conducting a brute-force attack against encrypted… | |
| Modificada | Media (4.3) | 1.1% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management Console/Dashboard. | |
| Modificada | Alta (7.5) | 2.5% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attackers to bypass authentication and obtain an admin session ID via unspecified vectors. | |
| Modificada | Baja (3.5) | 0.92% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file. | |
| Modificada | Media (4) | 0.94% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to read arbitrary files via a crafted URL. | |
| Modificada | Baja (3.5) | 0.85% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not properly encrypt system-backup data, which makes it easier for remote authenticated users to obtain sensitive information by reading a backup file, as demonstrated by obtaining… | |
| Modificada | Media (4) | 0.94% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to obtain the session tokens of arbitrary users by navigating within the Dashboard. | |
| Modificada | Media (4.9) | 0.85% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote authenticated users to reset the passwords of arbitrary administrative accounts via unspecified vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disable the server-side session token upon the closing of the Management Console/Dashboard, which makes it easier for remote attackers to hijack sessions by capturing a session… | |
| Modificada | Media (4.3) | 1.4% | — | Mcafee Email AND WEB SecurityMcafee Email Gateway | 22/8/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, allows remote attackers to inject arbitrary web script or HTML via vectors related to the McAfee Security Appliance Management… | |
| Modificada | Alta (7.8) | 1.4% | — | Mcafee Email AND WEB Security Appliance | 24/9/2009 | 16/6/2026 | Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However,… | |
| Modificada | Media (6) | 1.5% | — | Trendmicro Interscan WEB Security Suite | 17/2/2009 | 16/6/2026 | Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages. | |
| Modificada | Media (4.3) | 2.2% | — | Trendmicro Interscan WEB Security SuiteTrendmicro Interscan WEB Security Virtual Appliance | 17/2/2009 | 16/6/2026 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream… | |
| Modificada | Media (4.3) | 16% | — | Websense EnterpiseWebsense Reporting ToolsWebsense WEB Security Suite | 11/12/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the logon page in Web Reporting Tools portal in Websense Enterprise and Web Security Suite 6.3 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Alta (9.3) | 8.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+19 | 8/2/2007 | 16/6/2026 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable. | |
| Modificada | Media (4.3) | 2.1% | — | Symantec WEB Security | 30/1/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Symantec Web Security (SWS) before 3.0.1.85 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) error messages and (2) blocked page messages produced by SWS. |