Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1639 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Websight Directory System12/8/200216/6/2026
Cross-site scripting vulnerability in WebSight Directory System 0.1 allows remote attackers to execute arbitrary Javascript and gain access to the WebSight administrator via a new link submission containing the script in a website name.
ModificadaAlta (10)5.8%—Linux Directory Penguin Nslookup12/8/200216/6/2026
Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters.
ModificadaAlta (10)3.4%—Marcus S. Xenakis Directory.php26/7/200216/6/2026
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.
ModificadaMedia (5)3.3%💥 ExploitNortel Alteon Acedirector16/5/200216/6/2026
Nortle Alteon ACEdirector WebOS 9.0 con las carácteristicas de Balanceo de Carga de Servidor (Server Load Balancing, SLB) y de persistencia basada en cookies, permite a atacantes remotos determinar la IP real de un servidor web con una sesión medio cerrada, lo que causa que ACEdirector envíe paquetes del servidro sin…
ModificadaMedia (5)1.3%—IBM Tivoli Secureway Policy Director11/12/200116/6/2026
WebSeal en IBM Tivoli SecureWay Policy Director 3.8 permite a atacantes remotos causar la denegación de servicios (caida) mediante una URL que finalice con ..
ModificadaMedia (5)2.4%—Cisco Catalyst 2900xlCisco Catalyst 2948g-l3Cisco Catalyst 2950Cisco Catalyst 3500xl+715/11/200116/6/2026
Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table.
ModificadaMedia (5)7.5%💥 ExploitCosmicperl Directory PRO18/10/200116/6/2026
Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attackers to gain sensitive information via a .. (dot dot) in the SHOW parameter.
ModificadaAlta (7.5)3.4%—Vibechild Directory Manager5/9/200116/6/2026
edit_image.php in Vibechild Directory Manager before 0.91 allows remote attackers to execute arbitrary commands via shell metacharacters in the userfile_name parameter, which is sent unfiltered to the PHP passthru function.
ModificadaMedia (5)2.3%—IBM Tivoli Secureway Policy Director23/7/200116/6/2026
Directory traversal vulnerability in IBM Tivoli WebSEAL Policy Director 3.01 through 3.7.1 allows remote attackers to read arbitrary files or directories via encoded .. (dot dot) sequences containing "%2e" strings.
ModificadaAlta (7.5)6.3%—Oracle Internet Directory17/7/200116/6/2026
Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.8%—Oracle Internet Directory16/7/200116/6/2026
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.5%—IBM Secureway Directory16/7/200116/6/2026
IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)8.8%—Oracle Internet Directory16/7/200116/6/2026
Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.3%—SUN Iplanet Directory Server16/7/200116/6/2026
Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.6%—SUN Iplanet Directory Server16/7/200116/6/2026
Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)5.3%—IBM Secureway Directory16/7/200116/6/2026
Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.1%—SUN Iplanet Directory Server16/7/200116/6/2026
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.3%—Critical Path Injoin Directory ServerCritical Path Livecontent Directory16/7/200116/6/2026
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)3.7%💥 ExploitMicroburst Udirectory18/6/200116/6/2026
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the category_file field.
ModificadaAlta (7.5)2.2%—Netscape Directory Server2/6/200116/6/2026
Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.
ModificadaBaja (2.1)0.61%—Oracle Internet Directory2/6/200116/6/2026
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.
ModificadaMedia (4.6)0.21%—Coffeecup Software Coffeecup Direct FTPCoffeecup Software Coffeecup Free FTP12/2/200116/6/2026
CoffeeCup Direct and Free FTP clients uses weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.
ModificadaMedia (4.6)1.4%💥 ExploitOracle Internet DirectoryOracle8i19/12/200023/9/2026
Desbordamiento de búfer en oidldapd en Oracle 8.1.6 permite a usuarios locales obtener privilegios a través de un parámetro de línea de comandos 'connect' largo.
ModificadaMedia (5)3.6%💥 ExploitAnaconda Partners Foundation Directory19/12/200023/9/2026
Vulnerabilidad de salto de directorio en apexec.pl en Anaconda Foundation Directory permite a atacantes remotos leer archivos arbitrarios mediante un ataque de .. (punto punto).