Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 6.5% | — | Cisco PIXCisco Adaptive Security Appliance Software | 2/5/2007 | 16/6/2026 | Vulnerabilidad no especificada en Cisco Adaptive Security Appliance (ASA) y PIX 7.2 before 7.2(2)8, cuando utilizan Layer 2 Tunneling Protocol (L2TP) o Remote Management Access, permite a atacantes remotos evitar la validación LDAP y ganar privilegios a través de vectores desconocidos. | |
| Modificada | Alta (7.8) | 2.9% | — | Cisco PIXCisco Adaptive Security Appliance Software | 2/5/2007 | 16/6/2026 | Vulnerabilidad no especificada en Cisco Adaptive Security Appliance (ASA) y PIX 7.1 anterior a 7.1(2)49 y 7.2 anterior a 7.2(2)17 permite a atacantes remotos provocar denegación de servicio (recarga de dispositivo) a través de vectores desconocidos relacionados con el fin de la conexión VPN y el vencimiento de la… | |
| Modificada | Alta (7.8) | 4.4% | — | Cisco PIXCisco Adaptive Security Appliance Software | 2/5/2007 | 16/6/2026 | El agente transmisor DHCP en Cisco Adaptive Security Appliance (ASA) y PIX 7.2 permite a atacantes remotos provocar una denegación de servicio (abandono de paquetes) mediante un mensaje DHCPREQUEST o DHCPINFORM que provoca que múltiples mensajes DHCPACK sean enviados desde servidores DHCP al agente, lo cual consume la… | |
| Modificada | Alta (7.1) | 2.9% | — | Cisco PIXCisco Adaptive Security Appliance Software | 2/5/2007 | 16/6/2026 | Condición de carrera en el Cisco Adaptive Security Appliance (ASA) y en el PIX 7.1 anterior al 7.1(2)49 y el 7.2 anterior al 7.2(2)19, cuando se utiliza "VPNs SSL sin cliente", permite a atacantes remotos provocar una denegación de servicio (recargar el dispositivo) a través de "sesiones SSL no estándar". | |
| Modificada | Media (6.4) | 2.9% | — | Cisco Security Monitoring Analysis AND Response SystemCisco Adaptive Security Appliance Device Manager | 20/1/2007 | 16/6/2026 | El Cisco Security Monitoring, Analysis y Response System (CS-MARS) anterior 4.2.3 y Adaptive Security Device Manager (ASDM) anterior 5.2(2.54) no valida los certificados SSL/TLS o llaves públicas SSH cuando se conectan dispositivos, lo cual permite a atacantes remotos suplantar a estos dispositivos obteniendo… | |
| Modificada | Media (4.3) | 3.1% | — | Google Mini Search ApplianceGoogle Search Appliance | 2/12/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Google Search Appliance y Google Mini permite a un atacante remoto inyectar secuencias de comandos web o HTML a través de un parámetro q de codificación UTF-7. | |
| Modificada | Alta (10) | 3.6% | — | Cisco 2700 Wireless Location Appliance | 13/10/2006 | 16/6/2026 | Cisco 2700 Series Wireless Location Appliances anterior a 2.1.34.0 tienen por defecto el nombre de usuario administrador "root" y contraseña "password," lo cual permite a un atacante remoto obtener privilegios administrativos, aka Bug ID CSCsb92893. | |
| Modificada | Media (5) | 4.1% | 💥 Exploit | Google Mini Search Appliance | 27/9/2006 | 16/6/2026 | Google Mini 4.4.102.M.36 y anteriores, permite a un atacante remoto obtener información sensible a través de una petición directa a /search con un parámetro client no válido, lo cual revela la ruta en un mensaje de error. | |
| Modificada | Baja (2.6) | 2.0% | — | Cisco Guard Ddos Mitigation Appliance | 21/9/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Cisco Guard DDoS Mitigation Appliance anterior a 5.1(6), cuando anti-spoofing está habilitado, permite a atacantes remotos inyectar secuencias de comandos web o HTML de su elección vía cierta secuencia de caracteres en una URL que no es manejada… | |
| Modificada | Media (6.8) | 0.32% | — | Cisco PIX Firewall 501Cisco PIX Firewall 506Cisco PIX Firewall 515Cisco PIX Firewall 515e+5 | 23/8/2006 | 16/6/2026 | Cisco PIX 500 Series Security Appliances y ASA 5500 Series Adaptive Security Appliances, cuando ejecutan 7.0(x) hasta 7.0(5) y 7.1(x) hasta 7.1(2.4), y el Firewall Services Module (FWSM) 3.1(x) hasta 3.1(1.6), provoca que la contraseña EXEC, las contraseñas de usuario local, y la contraseña de activación se cambien a… | |
| Modificada | Media (5) | 6.9% | — | Cisco IOSCisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 Concentrator+17 | 27/7/2006 | 16/6/2026 | Protocolo Internet Key Exchange (IKE) version 1, implementado para Cisco IOS, VPN 3000 Concentrators, y PIX firewalls, permite a atacantes remotos provocar denegación de servicio (agotamiento de recursos) a través de un flood de paquetes IKE Phase-1 que exceden el ratio de expiración de la sesión. NOTA: se ha indicado… | |
| Modificada | Media (4.6) | 0.36% | — | IBM Network Appliance Data Ontap | 13/7/2006 | 16/6/2026 | Vulnerabilidad no especificada en NetApp Data ONTAP 7.0x hasta la 7.0.4P8D9, 7.1x, 7.1.0.1x, y 7.2RC1, RC2, y RC3, tal y como se usan en IBM N series Filers y otros productos, permite a usuarios no autorizados ganar privilegios de acceso a comandos privilegiados a través de vectores desconocidos, probablemente… | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Cisco Adaptive Security Appliance SoftwareCisco PIX FirewallCisco Firewall Services ModuleCisco PIX Firewall Software | 9/5/2006 | 16/6/2026 | Cisco PIX/ASA 7.1.x before 7.1(2) and 7.0.x before 7.0(5), PIX 6.3.x before 6.3.5(112), and FWSM 2.3.x before 2.3(4) and 3.x before 3.1(7), when used with Websense/N2H2, allows remote attackers to bypass HTTP access restrictions by splitting the GET method of an HTTP request into multiple packets, which prevents the… | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (5) | 1.6% | — | Webwasher CSM Appliance Suite | 23/12/2005 | 16/6/2026 | The encapsulation script mechanism in Webwasher CSM Appliance Suite 5.x uses case-sensitive detection of malicious tokens, which allows attackers to bypass script detection by using tokens that can be upper or lower case. NOTE: the vendor has stated that this problem could not be reproduced, and has asked the… | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Media (5.4) | 2.6% | — | Cisco Adaptive Security Appliance Software | 24/11/2005 | 16/6/2026 | Condición de carrera en Cisco Adaptive Security Appliance (ASA) 7.0(0), 7.0(2), Y 7.0(4), cuando corre una configuración Activo/En Espera y cuando la interfaz LAN de reserva falla, permite a atacantes remotos causar una denegación de servicio (fallo de cortafuegos en espera) enviando respuestas ARP suplantadas de la… | |
| Modificada | Alta (7.5) | 3.8% | — | Symantec Enterprise FirewallSymantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Gateway Security 300+6 | 23/11/2005 | 16/6/2026 | Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as… | |
| Modificada | Media (4.3) | 2.3% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via the proxystylesheet variable, which will be executed in the resulting error message. | |
| Modificada | Media (5) | 1.8% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to port scan arbitrary hosts via URLs with modified targets and ports, then comparing the resulting error messages to determine open and closed ports. | |
| Modificada | Alta (7.5) | 41% | 💥 Exploit | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2)… | |
| Modificada | Media (4.3) | 19% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to inject arbitrary Javascript, and possibly other web script or HTML, via a proxystylesheet variable that contains a malicious XSLT style sheet. | |
| Modificada | Media (5) | 3.6% | — | Google Mini Search ApplianceGoogle Search Appliance | 22/11/2005 | 16/6/2026 | Directory traversal vulnerability in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to determine the existence of arbitrary files via a relative path from a style sheet directory, then comparing the resulting error messages. |