Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 8.9% | — | Netscape Directory Server | 31/12/2004 | 16/6/2026 | Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 9.3% | 💥 Exploit | IBM Tivoli Directory Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers to view arbitrary files via a .. (dot dot) in the Template parameter. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Tivoli Access Manager FOR E-businessIBM Tivoli Access Manager Identity Manager SolutionIBM Tivoli Configuration ManagerIBM Tivoli Configuration Manager FOR ATM+2 | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in IBM Tivoli SecureWay Policy Director 3.8, Access Manager for e-business 3.9 to 5.1, Access Manager Identity Manager Solution 5.1, Configuration Manager 4.2, Configuration Manager for Automated Teller Machines 2.1.0, and IBM WebSphere Everyplace Server, Service Provider Offering for… | |
| Modificada | Alta (10) | 2.6% | — | Altiris Deployment Server Extension FOR IBM Director | 31/12/2004 | 16/6/2026 | AClient.exe in Altiris Deployment Solution 6.x and 5.x does not require authentication from the first Deployment Server that it connects to, which allows remote malicious servers to gain administrator access. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Media (5) | 26% | — | Microsoft DirectxMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+3 | 6/8/2004 | 16/6/2026 | El interfaz de programación de aplicación (API) IDirectPlay de Microsoft DirectPlay 7.0a a 9.0b, usado en Windows Server 2003 y anteriores, permite a atacantes remotos causar una denegación de servicio (caída de aplicación) mediante un paquete malformado. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Accipiter Direct Server | 17/2/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en Accipiter Direct Server 6.0 permite a atacantes remotos leer ficherso arbitrarios mediante secuencias barra invertida punto punto, codificadas como "%5c%2e%2e" en una petición HTTP. | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Macromedia DirectorMacromedia Flash Player | 5/1/2004 | 16/6/2026 | El Reproductor de Macromedia Flash en versiones anteriores a 7,0,19,0 almacena un fichero de datos de Flash en una localización predecible, accesible a navegadores web como Internet Explorer y Opera, lo que permite a a atacantes remotos leer ficheros restringidos mediante vulnerabilidades en navegadores web cuya… | |
| Modificada | Media (5) | 1.2% | — | SUN ONE Directory Server | 31/12/2003 | 16/6/2026 | Unknown vulnerability in ns-ldapd for Sun ONE Directory Server 4.16, 5.0, and 5.1 allows LDAP clients to cause a denial of service (service halt). | |
| Modificada | Alta (7.5) | 33% | — | Microsoft Directx | 27/8/2003 | 16/6/2026 | Múltiples desbordamientos en una librería MIDI Microsoft Windows DirectX (QUARTZ.DLL) permite a atacantes remotos ejecutar código arbitrario mediante un fichero midi (.mid) con (1) una cadena de texto o de copyright larga), o (2) un número de pistas largo, lo que conduce a un desbordamiento de búfer en el montón. | |
| Modificada | Media (5) | 1.6% | — | SUN Iplanet Directory ServerSUN ONE Directory Server | 27/8/2003 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorio en ViewLog de iPlanet Adminstration Server 5.1 (también llamado Sun ONE) permite a atacantes remotos leer ficheros arbitariosr mediente secuencias "..%2f" (punto punto parcialmente codificado). | |
| Modificada | Media (5) | 1.3% | — | Neomodus Direct Connect | 18/8/2003 | 16/6/2026 | NeoModus Direct Connect 1.0 build 9, y posiblemente otras versiones, permite a atacantes remotos causar una denegación de servicio (consumición de conexiónes y posiblemente de memoria) mediante una inundación de peticiones ConnectToMe con direcciones IP y puertos arbitrarios. | |
| Modificada | Alta (7.5) | 1.4% | — | Novell Edirectory | 31/3/2003 | 16/6/2026 | Novell eDirectory (eDir) 8.6.2 and Netware 5.1 eDir 85.x allows users with expired passwords to gain inappropriate permissions when logging in from Remote Manager. | |
| Modificada | Crítica (9.8) | 2.7% | — | Novell Edirectory | 31/12/2002 | 16/6/2026 | Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | HP Jetdirect | 4/10/2002 | 16/6/2026 | HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Directx Files Viewer Control | 24/9/2002 | 16/6/2026 | Buffer overflow in Microsoft DirectX Files Viewer ActiveX control (xweb.ocx) 2.0.6.15 and earlier allows remote attackers to execute arbitrary via a long File parameter. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Critical Path Injoin Directory Server | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 allow remote attackers to execute script as the administrator via administrator URLs with modified (1) LOCID or (2) OC parameters. | |
| Modificada | Alta (10) | 18% | — | Microsoft Metadirectory Services | 12/8/2002 | 16/6/2026 | Microsoft Metadirectory Services (MMS) 2.2 permite que atacantes remotos se salten la autentificación y modifiquen datos importantes usando un cliente LDAP para conectarse directamente a MMS y saltarse las comprobaciones de credenciales para MMS. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Critical Path Injoin Directory Server | 12/8/2002 | 16/6/2026 | iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators to read arbitrary files by specifying the target file in the LOG parameter. | |
| Modificada | Alta (10) | 6.2% | — | Linux Directory Penguin Traceroute | 12/8/2002 | 16/6/2026 | Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. |