Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2840▲ 88 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
–

1724 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (1.2)0.65%💥 ExploitMandrakesoft Mandrake Multi Network FirewallLinux KernelMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server27/8/200316/6/2026
Una condición de carrera en la manera que los punteros env_start y env_end son inicializados en la llamada al sistema execve y usada en fs/proc/base.c en Linux 2.4 permite a usuarios locales causar una denegación de servicio (caída).
ModificadaMedia (5)1.3%—Privacyware Privatefirewall2/7/200316/6/2026
Privacyware Privatefirewall 3.0 no bloquea ciertos paquetes entrantes cuando está en modo "Filtrar Tráfico de Intenet" o "Denegar Tráfico de Internet", lo que permite a atacantes remotos identificar servicios en ejecución mediante escaneos FIN O Xmas (usando paquetes con estas banderas activas)
ModificadaAlta (7.5)6.9%💥 ExploitSymantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security9/6/200316/6/2026
Symantec Raptor Firewall 6.5 y 6.5.3, Enterprise Firewall 6.5.2 y 7.0, VelociRaptor modelos 500/700/1000 y 1100/1200/1300, y Gateway Security 5110/5200/5300 generan secuencias numéricas iniciales (ISN) fácilmente predecibles, lo que permitiría a atacantes remotos falsear conexiones.
ModificadaAlta (7.5)3.8%—Kerio Personal Firewall 212/5/200316/6/2026
Kerio Personal Firewall (KPF) 2.1.4 y anteriores permiten a atacantes remotos ejecutar comandos administrativos olisqueando (sniffing) paquetes de una sesión válida y respondiéndolos contra el servidor de administración remota.
ModificadaAlta (7.5)69%💥 ExploitKerio Personal Firewall 212/5/200316/6/2026
Desbordamiento de búfer en el proceso de autenticación de Kerio Personal Firewall (KPF) 2.1.4 y anteriores permite a atacantes remotos ejecutar código arbitrario con un paquete de establecimiento de conexión (handshake).
ModificadaAlta (7.5)1.4%—Symantec Enterprise Firewall2/4/200316/6/2026
El proxy HTTP de Symantec Enterprise Firewall (SEF) 7.0 permite a usuarios del proxy evitar la comprobación de patrones de URLs bloqueadas mediante peticiones codificadas en la URL con escapes, Unicode, o UTF-8.
ModificadaMedia (5)2.4%—Symantec Enterprise FirewallSymantec Raptor Firewall31/3/200316/6/2026
Secure Webserver 1.1 en Raptor 6.5 y Symantec Enterprise Firewall 6.5.2 permite a atacantes remotos la identificación de direcciones IP de equipos en red mediante una petición CONNECT, que genera un mensajes de error distinto en caso de que el equipo este presente.
ModificadaAlta (10)3.5%—MIT Kerberos FTP ClientRedhat LinuxMandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake Linux19/2/200316/6/2026
El cliente de ftp Kerberos permite a sitios FTP remotos ejecutar código arbitrario mediante un carácter de tubería (|) en un nombre de fichero que recupera el cliente
ModificadaMedia (4.3)2.5%💥 ExploitSymantec Norton Personal Firewall31/12/200216/6/2026
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets.
ModificadaMedia (5)2.0%—Cisco PIX Firewall Software31/12/200216/6/2026
Buffer overflow in Cisco PIX Firewall 5.2.x to 5.2.8, 6.0.x to 6.0.3, 6.1.x to 6.1.3, and 6.2.x to 6.2.1 allows remote attackers to cause a denial of service via HTTP traffic authentication using (1) TACACS+ or (2) RADIUS.
ModificadaAlta (7.5)1.3%—Symantec Norton Personal Firewall31/12/200216/6/2026
The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).
ModificadaMedia (5)1.3%—Symantec Firewall VPN Appliance 100Symantec Firewall VPN Appliance 200Symantec Firewall VPN Appliance 200r31/12/200216/6/2026
Symantec Firewall/VPN Appliance 100 through 200R hardcodes the administrator's MAC address inside the firewall's configuration, which allows remote attackers to spoof the administrator's MAC address and perform an ARP poisoning man-in-the-middle attack to obtain the administrator's password.
ModificadaMedia (5)1.6%—Tiny Software Tiny Personal Firewall31/12/200216/6/2026
Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module.
ModificadaAlta (7.5)1.5%—Symantec Norton Personal Firewall31/12/200216/6/2026
Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan.
ModificadaAlta (10)2.2%—Symantec Sygate Personal Firewall31/12/200216/6/2026
Sygate personal firewall 5.0 could allow remote attackers to bypass firewall filters via spoofed (1) source IP address of 127.0.0.1 or (2) network address of 127.0.0.0.
ModificadaMedia (6.4)1.2%—Cisco PIX Firewall Software31/12/200216/6/2026
Cisco PIX Firewall 6.0.3 and earlier, and 6.1.x to 6.1.3, do not delete the duplicate ISAKMP SAs for a user's VPN session, which allows local users to hijack a session via a man-in-the-middle attack.
ModificadaMedia (5)1.9%—Symantec Enterprise FirewallSymantec Raptor FirewallSymantec Velociraptor31/12/200216/6/2026
Multiple buffer overflows in Symantec Raptor Firewall 6.5 and 6.5.3, Enterprise Firewall 6.5.2 and 7.0, VelociRaptor 500/700/1000 and 1100/1200/1300, and Gateway Security 5110/5200/5300 allow remote attackers to cause a denial of service (service termination) via (1) malformed RealAudio (rad) packets that are not…
ModificadaMedia (5)1.6%—Kerio Personal Firewall31/12/200216/6/2026
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood.
ModificadaMedia (4.9)0.85%—Checkpoint Firewall-131/12/200216/6/2026
Check Point FireWall-1 4.1 and Next Generation (NG), with UserAuth configured to proxy HTTP traffic only, allows remote attackers to pass unauthorized HTTPS, FTP and possibly other traffic through the firewall.
ModificadaMedia (5)49%—Checkpoint Vpn-1 Firewall-131/12/200216/6/2026
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses before the password is supplied or (2)…
ModificadaAlta (7.5)2.0%—Atguard Personal Firewall31/12/200216/6/2026
AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames.
ModificadaMedia (5)1.7%—Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security28/10/200216/6/2026
El componente de proxy web en Symantec Enterprise Firewall (SEF) 6.5.2 a 7.0, Raptor Firewall 6.5 y 6.5.3, VelociRaptor, y Symantec Gateway Security permite a atacantes remotos causar una denegación de servicio (agotamiento de recursos de conexiones) mediante múltiples peticiones de conexión a dominios cuyo servidor…
ModificadaMedia (5)1.7%—IBM Secureway Firewall28/10/200216/6/2026
IBM SecureWay Firewall anteriores a 4.2.2 realiza procesamiento extra antes de determinar que un paquete es inválido y ser descartado, lo que permite a atacantes causar una denegación de servicio (agotamiento de recursos) mediante una inundación de paquetes TCP malformados sin ningun flag establecido.
ModificadaMedia (5)1.7%—Watchguard FireboxWatchguard Soho Firewall4/10/200216/6/2026
Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) via a malformed packet containing tab characters to TCP port 4110.
ModificadaAlta (7.1)3.3%—Cisco IOSCisco PIX Firewall SoftwareCisco Css11000 Content Services SwitchCisco Catos4/10/200216/6/2026
Cisco IOS 12.0 through 12.2, when supporting SSH, allows remote attackers to cause a denial of service (CPU consumption) via a large packet that was designed to exploit the SSH CRC32 attack detection overflow (CVE-2001-0144).