Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.5% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 21/12/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack. | |
| Modificada | Media (5.5) | 1.2% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 21/12/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111. | |
| Modificada | Media (5.5) | 1.5% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 21/12/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments. | |
| Modificada | Media (5.3) | 1.6% | — | Cisco Virtual Wide Area Application ServicesCisco Wide Area Application Services | 5/10/2017 | 17/6/2026 | A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an ICA application optimization-related process to restart, resulting in a partial denial of service (DoS) condition. The… | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Wide Area Application Services | 5/10/2017 | 17/6/2026 | A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability is due to certain file-handling inefficiencies of the affected system. An… | |
| Modificada | Media (5.3) | 3.1% | — | Cisco Wide Area Application Services | 21/9/2017 | 17/6/2026 | A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition. The vulnerability is due to lack of input validation… | |
| Modificada | Media (5.5) | 1.2% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 9/9/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service. | |
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Geneko Gwr352 3G Router FirmwareGeneko Gwr352wv Wide Voltage 3G Router FirmwareGeneko Gwr252 Edge Router FirmwareGeneko Gwr202 Gprs Router Firmware | 19/7/2017 | 17/6/2026 | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file. | |
| Modificada | Media (5.3) | 1.7% | — | Cisco Wide Area Application Services | 10/7/2017 | 17/6/2026 | A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker to retrieve completed reports from an affected system, aka Information Disclosure. This vulnerability affects the following products if they are running an affected… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Wide Area Application Services | 10/7/2017 | 17/6/2026 | A vulnerability in the Server Message Block (SMB) protocol of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device due to a process restarting unexpectedly and creating Core Dump files. More Information:… | |
| Modificada | Alta (7.8) | 1.7% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 8/7/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Wide Area Application Services | 4/7/2017 | 17/6/2026 | A vulnerability in the ingress processing of fragmented TCP packets by Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause the WAASNET process to restart unexpectedly, causing a denial of service (DoS) condition. More Information: CSCvc57428. Known Affected Releases:… | |
| Modificada | Alta (7.8) | 2.9% | — | Nasm Netwide AssemblerCanonical Ubuntu Linux | 29/6/2017 | 17/6/2026 | In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function (called by pp_getline()) - it is used again at multiple positions later that could cause multiple damages. For example,… | |
| Modificada | Media (6.8) | 1.7% | — | Cisco Wide Area Application Services | 3/5/2017 | 17/6/2026 | A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, and 6.2.3a could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition where the WAN optimization could stop functioning while the process restarts. The vulnerability… | |
| Modificada | Media (5.9) | 1.7% | — | Cisco Wide Area Application Services | 27/10/2016 | 17/6/2026 | A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to high consumption of disk space. The user would see a performance degradation. More Information: CSCva03095. Known… | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco Wide Area Application Services | 27/1/2016 | 17/6/2026 | cifs-ao in the CIFS optimization functionality on Cisco Wide Area Application Service (WAAS) and Virtual WAAS (vWAAS) devices 5.x before 5.3.5d and 5.4 and 5.5 before 5.5.3 allows remote attackers to cause a denial of service (resource consumption and device reload) via crafted network traffic, aka Bug ID CSCus85330. | |
| Modificada | Media (4.3) | 1.9% | — | Wideimage Project Wideimage | 14/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the applyConvolution demo in WideImage 11.02.19 allows remote attackers to inject arbitrary web script or HTML via the matrix parameter to demo/index.php. | |
| Modificada | Media (5) | 1.4% | — | Cisco Wide Area Application Services | 16/5/2015 | 17/6/2026 | The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of service (module reload) via an invalid field in a Negotiate Protocol request, aka Bug ID CSCuo75645. | |
| Modificada | Media (5) | 3.0% | — | Cisco Wide Area Application Services | 29/5/2014 | 17/6/2026 | Cisco Wide Area Application Services (WAAS) 5.3(.5a) and earlier, when SharePoint acceleration is enabled, does not properly parse SharePoint responses, which allows remote attackers to cause a denial of service (application-optimization handler reload) via a crafted SharePoint application, aka Bug ID CSCue47674. | |
| Modificada | Alta (9.3) | 2.4% | — | Cisco Wide Area Application Services | 26/5/2014 | 17/6/2026 | Cisco Wide Area Application Services (WAAS) 5.1.1 before 5.1.1e, when SharePoint prefetch optimization is enabled, allows remote SharePoint servers to execute arbitrary code via a malformed response, aka Bug ID CSCue18479. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Wide Area Application Services Mobile | 8/11/2013 | 16/6/2026 | Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773. | |
| Modificada | Alta (9) | 4.2% | — | Cisco Wide Area Application ServicesCisco Application AND Content Networking System SoftwareCisco Enterprise Content Delivery Network SoftwareCisco Internet Streamer Content Delivery System+4 | 1/8/2013 | 16/6/2026 | The web framework in Cisco WAAS Software before 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1; Cisco ACNS Software 4.x and 5.x before 5.5.29.2; Cisco ECDS Software 2.x before 2.5.6; Cisco CDS-IS Software 2.x before 2.6.3.b50 and 3.1.x before 3.1.2b54; Cisco VDS-IS Software 3.2.x before… | |
| Modificada | Alta (10) | 6.0% | — | Cisco Wide Area Application Services | 1/8/2013 | 16/6/2026 | The web service framework in Cisco WAAS Software 4.x and 5.x before 5.0.3e, 5.1.x before 5.1.1c, and 5.2.x before 5.2.1 in a Central Manager (CM) configuration allows remote attackers to execute arbitrary code via a crafted POST request, aka Bug ID CSCuh26626. | |
| Modificada | Baja (2.1) | 0.18% | — | Pawel Jakub Dawidek Geli | 21/8/2012 | 16/6/2026 | The geli encryption provider 7 before r239184 on FreeBSD 10 uses a weak Master Key, which makes it easier for local users to defeat a cryptographic protection mechanism via a brute-force attack. | |
| Modificada | Media (5) | 1.2% | — | Cisco Wide Area Application Services | 6/8/2012 | 16/6/2026 | Cisco Wide Area Application Services (WAAS) appliances with software 4.4, 5.0, and 5.1 include a one-way hash of a password within output text, which might allow remote attackers to obtain sensitive information via a brute-force attack on the hash string, aka Bug ID CSCty17279. |