Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 5.2% | — | Cisco Firewall Services ModuleCisco VPN 3000 Concentrator Series SoftwareCisco IOSCisco Adaptive Security Appliance Software+4 | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in multiple Cisco products allow remote attackers to cause a denial of service (device reset) via certain malformed IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details… | |
| Modificada | Alta (7.5) | 1.6% | — | Network Appliance Data OntapAI | 27/10/2005 | 16/6/2026 | Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identity. | |
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Media (6.4) | 1.0% | — | Nexland Pro800turboSymantec Firewall VPN Appliance 200rSymantec Gateway Security 360Symantec Gateway Security 460 | 2/5/2005 | 16/6/2026 | The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted… | |
| Modificada | Alta (7.8) | 1.8% | — | Network Appliance Data OntapNetwork Appliance Netcache | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Network Appliance NetCache 5.2 and Data ONTAP 6.0 allows remote attackers to cause a denial of service (panic and reboot) and possibly other impacts via unknown attack vectors, possibly related to unspecified worms, as identified by bug ID | |
| Modificada | Media (5) | 3.2% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 uses a default read/write SNMP community string, which allows remote attackers to alter the firewall's configuration file. | |
| Modificada | Media (5) | 3.7% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security+6 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 allow remote attackers to cause a denial of service (device freeze) via a fast UDP port scan on the WAN interface. | |
| Modificada | Media (5) | 3.9% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200rSymantec Gateway Security 320+8 | 31/12/2004 | 16/6/2026 | Symantec Enterprise Firewall/VPN Appliances 100, 200, and 200R running firmware before 1.63 and Gateway Security 320, 360, and 360R running firmware before 622 allow remote attackers to bypass filtering and determine whether the device is running services such as tftpd, snmpd, or isakmp via a UDP port scan with a… | |
| Modificada | Media (6.8) | 2.3% | — | Infoblox DNS ONE Appliance | 6/12/2004 | 16/6/2026 | Vulnerabilidad de scripts en sitios cruzados (XSS) en Infoblox DNS One con firmware 2.4.0-8 permite a atacantes remotos ejecutar scripts como otros usuarios mediante la opción (1) CLIENTID o (2) HOSTNAME de una petición DHCP. | |
| Modificada | Alta (10) | 17% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | El demonio DHCP (DHCPD) de ISC DHCP 3.0.1rc12 y 3.0.1rc13, cuando se compila en entornos que no proveen la función vsnprintf, usa ficheros de inclusión de C que definen vsnprintf usando la función menos segura vsprintf, lo que puede ocasionar vulnerabilidades de desbordamiento de búfer que permitan una denegación de… | |
| Modificada | Alta (10) | 45% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en la capacidad de registro de sucesos (logging) del demonio DHCP (DHCPD) de ISC DHCP 3.0.1rc12 y 3.01rc13 permite a atacantes remotos causar una denegación de servión (caída del servidor) y posiblemente ejecutar código arbitrario mediante multiples opciones de nombre de máquina (hostname) en… | |
| Modificada | Alta (7.5) | 1.4% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200r | 15/3/2004 | 16/6/2026 | Symantec FireWall/VPN Appliance model 200 registra la contraseña de la página de administración en texto claro, que puede ser guardad en caché en el sistema local del administrador o en un proxy, lo que podría permitir a atacantes robar la contraseña y ganar privilegios. | |
| Modificada | Media (5) | 1.3% | — | Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200r | 31/12/2002 | 16/6/2026 | Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password. | |
| Modificada | Media (5) | 1.3% | — | Checkpoint Firewall-1Checkpoint Vpn-1Nokia Firewall Appliance | 8/10/2001 | 16/6/2026 | Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way… | |
| Modificada | Alta (7.5) | 1.6% | — | Network Appliance Netcache | 5/7/2001 | 16/6/2026 | The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device. | |
| Modificada | Alta (7.5) | 1.9% | — | Nokia Ip440 Firewall VPN Appliance | 2/6/2001 | 16/6/2026 | Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL. | |
| Modificada | Media (5) | 1.8% | — | SnmpNetwork Appliance Netcache | 7/4/1999 | 9/10/2026 | The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it. |