Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1724 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.51%—Webroot Software Desktop Firewall14/10/200516/6/2026
Stack-based buffer overflow in PWIWrapper.dll for Webroot Desktop Firewall before 1.3.0build52 allows local users to execute arbitrary code as SYSTEM by sending a crafted DeviceIoControl command, then removing an allowed program from the firewall list.
ModificadaMedia (4.6)0.38%—Webroot Software Desktop Firewall14/10/200516/6/2026
Webroot Desktop Firewall before 1.3.0build52 allows local users to disable the firewall, even when password protection is enabled, via certain DeviceIoControl commands.
ModificadaAlta (7.5)53%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
ModificadaMedia (6.4)1.4%—Barracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin…
ModificadaMedia (5)8.8%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
ModificadaBaja (1.2)0.30%—Giptables Firewall9/6/200516/6/2026
GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.
ModificadaAlta (7.5)1.1%—Fortinet Firewall1/6/200516/6/2026
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.
ModificadaAlta (7.5)1.0%—Clam Anti-virus ClamavGibraltar FirewallSquid24/5/200516/6/2026
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.
ModificadaBaja (2.1)0.33%—Webroot Software MY Firewall Plus18/5/200516/6/2026
Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files.
ModificadaAlta (7.5)1.2%—Cisco Firewall Services Module11/5/200516/6/2026
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).
ModificadaMedia (4.6)0.34%—Kerio Personal Firewall2/5/200516/6/2026
Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions.
ModificadaMedia (5)1.6%—Symantec Enterprise FirewallSymantec VelociraptorSymantec Gateway Security 5300Symantec Gateway Security 54002/5/200516/6/2026
Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites.
ModificadaAlta (7.5)1.3%—Barracuda Networks Barracuda Spam Firewall2/5/200516/6/2026
Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.
ModificadaMedia (6.4)1.0%—Nexland Pro800turboSymantec Firewall VPN Appliance 200rSymantec Gateway Security 360Symantec Gateway Security 4602/5/200516/6/2026
The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted…
ModificadaAlta (7.5)2.6%—Kerio MailserverKerio Personal FirewallKerio Winroute Firewall2/5/200516/6/2026
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.
ModificadaMedia (4.6)0.75%—Ingate Firewall2/5/200516/6/2026
Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources.
ModificadaMedia (5)1.6%—Kerio MailserverKerio Personal FirewallKerio Winroute Firewall29/4/200516/6/2026
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic…
ModificadaBaja (2.1)0.51%—Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1114/4/200516/6/2026
El soporte de ELF de 64 bits en los kernel de Linux 2.6 anteriores a 2.6.10 en arquitecturas de 64 bits no verifica adecuadamente solapamientos en asignaciones de memoria VMA (virtual memory address), lo que permite a usuarios locales causar una denegación de servicio (caída del sistema) o ejecutar código de su…
ModificadaMedia (6.2)2.9%💥 ExploitAvaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1614/4/200516/6/2026
Condición de carrera en las llamadas de funciones (1) load_elf_library y (2) binfmt_aout de uselib de los kernel de Linux 2.4 a 2.429-rc2 y 2.6 a 2.6.10 permite a usuarios locales ejecutar código de su elección manipulando el descriptor WMA.
ModificadaAlta (9.3)17%💥 ExploitHP Java Sdk-rteSUN JDKSUN JRESymantec Enterprise Firewall+41/3/200516/6/2026
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API…
ModificadaAlta (7.2)1.4%—Mandrakesoft Mandrake Multi Network FirewallTodd Miller SudoDebian LinuxMandrakesoft Mandrake Linux+31/3/200516/6/2026
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
ModificadaBaja (2.1)0.41%—Mandrakesoft Mandrake Multi Network FirewallOpensslGentoo LinuxMandrakesoft Mandrake Linux+19/2/200516/6/2026
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)0.29%—Kerio MailserverKerio ServerfirewallKerio Winroute Firewall10/1/200516/6/2026
Kerio Winroute Firewall anteriores a 6.0.9, Server Firewall anteriores a 1.0.1, y MailServer anteriores a 6.0.5, cuando se instala en sistemas basados en Windows, no modifica las listas de control de acceso (ACL) de ficheros críticos, lo que permite a usuarios locales con privilegios de "Usuarios Avanzados" modificar…
ModificadaMedia (5)3.2%💥 ExploitKerio Personal Firewall10/1/200516/6/2026
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field.
ModificadaBaja (2.1)0.21%—Kerio MailserverKerio ServerfirewallKerio Winroute Firewall10/1/200516/6/2026
Kerio Winroute Firewall anteriores a 6.0.7, ServerFirewall anteriores a 1.0.1, y MailServer anteriores a 6.0.5 usan cifrado simétrico para contraseñas de usuario, lo que permite a atacantes descifrar la base de datos de usuarios y obtener las contraseñas extrayendo la clave secreta del software.
Orbitaley — Vulnerabilidades