Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2792▲ 39 respecto a la semana anterior
Críticas / altas1284▼ 238 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.51% | — | Webroot Software Desktop Firewall | 14/10/2005 | 16/6/2026 | Stack-based buffer overflow in PWIWrapper.dll for Webroot Desktop Firewall before 1.3.0build52 allows local users to execute arbitrary code as SYSTEM by sending a crafted DeviceIoControl command, then removing an allowed program from the firewall list. | |
| Modificada | Media (4.6) | 0.38% | — | Webroot Software Desktop Firewall | 14/10/2005 | 16/6/2026 | Webroot Desktop Firewall before 1.3.0build52 allows local users to disable the firewall, even when password protection is enabled, via certain DeviceIoControl commands. | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | |
| Modificada | Media (6.4) | 1.4% | — | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 8/9/2005 | 16/6/2026 | Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | |
| Modificada | Baja (1.2) | 0.30% | — | Giptables Firewall | 9/6/2005 | 16/6/2026 | GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file. | |
| Modificada | Alta (7.5) | 1.1% | — | Fortinet Firewall | 1/6/2005 | 16/6/2026 | Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges. | |
| Modificada | Alta (7.5) | 1.0% | — | Clam Anti-virus ClamavGibraltar FirewallSquid | 24/5/2005 | 16/6/2026 | Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected. | |
| Modificada | Baja (2.1) | 0.33% | — | Webroot Software MY Firewall Plus | 18/5/2005 | 16/6/2026 | Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary files by saving log files. | |
| Modificada | Alta (7.5) | 1.2% | — | Cisco Firewall Services Module | 11/5/2005 | 16/6/2026 | Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs). | |
| Modificada | Media (4.6) | 0.34% | — | Kerio Personal Firewall | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Kerio Personal Firewall 4.1.2 and earlier allows local users to bypass firewall rules via a malicious process that impersonates a legitimate process that has fewer restrictions. | |
| Modificada | Media (5) | 1.6% | — | Symantec Enterprise FirewallSymantec VelociraptorSymantec Gateway Security 5300Symantec Gateway Security 5400 | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the DNSd proxy, as used in Symantec Gateway Security 5400 2.x and 5300 1.x, Enterprise Firewall 7.0.x and 8.x, and VelociRaptor 1100/1200/1300 1.5, allows remote attackers to poison the DNS cache and redirect users to malicious sites. | |
| Modificada | Alta (7.5) | 1.3% | — | Barracuda Networks Barracuda Spam Firewall | 2/5/2005 | 16/6/2026 | Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam. | |
| Modificada | Media (6.4) | 1.0% | — | Nexland Pro800turboSymantec Firewall VPN Appliance 200rSymantec Gateway Security 360Symantec Gateway Security 460 | 2/5/2005 | 16/6/2026 | The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, might send SMTP traffic to a trusted network through an untrusted… | |
| Modificada | Alta (7.5) | 2.6% | — | Kerio MailserverKerio Personal FirewallKerio Winroute Firewall | 2/5/2005 | 16/6/2026 | The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods. | |
| Modificada | Media (4.6) | 0.75% | — | Ingate Firewall | 2/5/2005 | 16/6/2026 | Ingate Firewall 4.1.3 and earlier does not terminate the PPTP session for an active user when the administrator disables that user from a resource, which could allow remote authenticated users to retain unauthorized access to resources. | |
| Modificada | Media (5) | 1.6% | — | Kerio MailserverKerio Personal FirewallKerio Winroute Firewall | 29/4/2005 | 16/6/2026 | The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic… | |
| Modificada | Baja (2.1) | 0.51% | — | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+11 | 14/4/2005 | 16/6/2026 | El soporte de ELF de 64 bits en los kernel de Linux 2.6 anteriores a 2.6.10 en arquitecturas de 64 bits no verifica adecuadamente solapamientos en asignaciones de memoria VMA (virtual memory address), lo que permite a usuarios locales causar una denegación de servicio (caída del sistema) o ejecutar código de su… | |
| Modificada | Media (6.2) | 2.9% | 💥 Exploit | Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+16 | 14/4/2005 | 16/6/2026 | Condición de carrera en las llamadas de funciones (1) load_elf_library y (2) binfmt_aout de uselib de los kernel de Linux 2.4 a 2.429-rc2 y 2.6 a 2.6.10 permite a usuarios locales ejecutar código de su elección manipulando el descriptor WMA. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | HP Java Sdk-rteSUN JDKSUN JRESymantec Enterprise Firewall+4 | 1/3/2005 | 16/6/2026 | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API… | |
| Modificada | Alta (7.2) | 1.4% | — | Mandrakesoft Mandrake Multi Network FirewallTodd Miller SudoDebian LinuxMandrakesoft Mandrake Linux+3 | 1/3/2005 | 16/6/2026 | sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname. | |
| Modificada | Baja (2.1) | 0.41% | — | Mandrakesoft Mandrake Multi Network FirewallOpensslGentoo LinuxMandrakesoft Mandrake Linux+1 | 9/2/2005 | 16/6/2026 | The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.29% | — | Kerio MailserverKerio ServerfirewallKerio Winroute Firewall | 10/1/2005 | 16/6/2026 | Kerio Winroute Firewall anteriores a 6.0.9, Server Firewall anteriores a 1.0.1, y MailServer anteriores a 6.0.5, cuando se instala en sistemas basados en Windows, no modifica las listas de control de acceso (ACL) de ficheros críticos, lo que permite a usuarios locales con privilegios de "Usuarios Avanzados" modificar… | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Kerio Personal Firewall | 10/1/2005 | 16/6/2026 | The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system freeze from infinite loop) via a (1) TCP, (2) UDP, or (3) ICMP packet with a zero length IP Option field. | |
| Modificada | Baja (2.1) | 0.21% | — | Kerio MailserverKerio ServerfirewallKerio Winroute Firewall | 10/1/2005 | 16/6/2026 | Kerio Winroute Firewall anteriores a 6.0.7, ServerFirewall anteriores a 1.0.1, y MailServer anteriores a 6.0.5 usan cifrado simétrico para contraseñas de usuario, lo que permite a atacantes descifrar la base de datos de usuarios y obtener las contraseñas extrayendo la clave secreta del software. |