Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
1622 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 57% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+3 | 23/12/2004 | 16/6/2026 | Internet Explorer 6.1 SP1 y anteriores, y posiblemente otras versiones, permiten a atacantes remotos causar una denegación de servicio (caída de aplicación por "corrupción de memoria") mediante ciertos elementos de Hoja de Estilos en Cascada (CSS), como se ha demostrado usanto la cadena "<STYLE>@;/*", posiblemente… | |
| Modificada | Alta (7.5) | 6.3% | — | Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+15 | 21/12/2004 | 16/6/2026 | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow. | |
| Modificada | Media (5) | 4.2% | — | Brocade SilkwormBrocade Silkworm Fiber Channel SwitchEngenio Storage ControllerIBM Ds4100+2 | 4/9/2004 | 16/6/2026 | Engenio/LSI Logic storage controllers, as used in products such as Storagetek D280, and IBM DS4100 (formerly FastT 100) and Brocade SilkWorm Switches, allow remote attackers to cause a denial of service (freeze and possible data corruption) via crafted TCP packets. | |
| Modificada | Media (5) | 34% | — | Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+14 | 18/8/2004 | 16/6/2026 | Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by… | |
| Modificada | Alta (7.2) | 0.42% | — | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Múltiples vulnerabilidades desconocidas en el kernel de Linux 2.4 y 2.6 permiten a usuarios locales ganar privilegios o acceder a memoria del kernel, como se ha encontrado mediante la herramienta de comprobación de código fuente "Sparse". | |
| Modificada | Alta (7.2) | 24% | — | Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en Microsoft Internet Information Server (IIS) 4.0 permite a usuarios locales ejecutar código de su elección mediante la función de redirección. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Avaya Ip600 Media ServersMicrosoft IEAvaya Definity ONE Media ServerAvaya S8100+4 | 6/8/2004 | 16/6/2026 | Vulnerabilidad basada en la pila en el Programador de Tareas de Windows 2000 y XP, e Internet Explorer 6 en Windows NT 4.0 permite a atacantes remotos o locales ejecutar código de su elección mediante un fichero .job conteniendo parámetros grandes, como se ha demostrado utlizando Internet Explorer y accediendo a un… | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | El kernel de Linux 2.4.2x y 2.6.x para x86 permite a usuarios locales causar una denegación de servicio (caída del sistema), posiblemente mediante un bucle infinito que dispara un manejador de señal con una cierta secuencia de instrucciones fsave y fstor, originalmente demostrado con el programa "crash.c". | |
| Modificada | Media (5) | 16% | — | Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Microsoft Outlook Express 5.5 y 6 permiten a atacantes causar una denegación de servicio (caída de la aplicación) mediante una cabecera de correo electrónico malformada. | |
| Modificada | Alta (10) | 45% | — | Avaya Ip600 Media ServersAvaya Definity ONE Media ServerAvaya S8100Avaya Modular Messaging Message Storage Server+7 | 6/8/2004 | 16/6/2026 | Vulnerabilidad basada en el montón en el programa HtmlHelp (hh.exe) en ayuda HTML de Microsoft Windows 98, Me, NT, 4.0, 2000, XP y Server 2003 permite a atacantes remotos ejecutar órdenes de su elección mediante un fichero .CHML con un campo de longitud largo, una vulnerabilidad distinta de CAN-2003-1041. | |
| Modificada | Alta (7.2) | 0.37% | — | SUN Storedge 3310 Scsi ArraySUN Storedge 3510 FC ArraySUN Enterprise Storage Manager | 21/6/2004 | 16/6/2026 | Unknown vulnerability in Sun StorEdge Enterprise Storage Manager (ESM) 2.1 for Solaris 8 and Solaris 9 allows local users with the "ESMUser" role to gain root access. | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | |
| Modificada | Media (4.6) | 0.31% | — | Iomega Network Attached Storage | 31/12/2002 | 16/6/2026 | Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled. | |
| Modificada | Alta (7.5) | 4.0% | — | IBM Tivoli Storage Manager | 3/7/2002 | 16/6/2026 | Desbordamiento de búfer en Tivoli Storage Manager TSM : Server o Storage Agents 3.1 a la 5.1 TSM Client Acceptor Service 4.2 y 5.1 permite a atacantes remotos realizar un ataque de Denegación de Servicio (caida) y posiblemente la ejecución de código arbitrario mediante una petición HTTP GET larga a los puertos 1580 o… | |
| Modificada | Media (5) | 2.0% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (router crash) via an HTTP request with large headers. | |
| Modificada | Media (5) | 2.2% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows attackers to read configuration files without authorization. | |
| Modificada | Media (5) | 3.3% | — | Cisco SN 5420 Storage Router Firmware | 9/1/2002 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(5) and earlier allows remote attackers to cause a denial of service (halt) via a fragmented packet to the Gigabit interface. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxAvaya CvlanAvaya Integrated Management SuitAvaya Interactive Response+3 | 31/12/2001 | 16/6/2026 | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. | |
| Modificada | Media (5) | 1.9% | — | Cisco SN 5420 Storage Router Firmware | 11/7/2001 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows remote attackers to cause a denial of service (reboot) via a series of connections to TCP port 8023. | |
| Modificada | Alta (10) | 4.0% | — | Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+11 | 12/3/2001 | 16/6/2026 | Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name. | |
| Modificada | Media (5) | 1.6% | — | Storagesoft Imagecast IC3 | 12/3/2001 | 16/6/2026 | ImageCast Control Center 4.1.0 allows remote attackers to cause a denial of service (resource exhaustion or system crash) via a long string to port 12002. | |
| Modificada | Media (4.6) | 0.49% | — | Cisco SN 5420 Storage Router Firmware | 8/1/2001 | 16/6/2026 | Cisco SN 5420 Storage Router 1.1(3) and earlier allows local users to access a developer's shell without a password and execute certain restricted commands without being logged. |