Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 192 respecto a la semana anterior
Críticas / altas1314▼ 122 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)250▲ 236 respecto a la semana anterior
1724 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Watchguard Soho Firewall | 4/10/2002 | 16/6/2026 | The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name. | |
| Modificada | Alta (7.5) | 0.70% | — | Cisco PIX Firewall | 4/10/2002 | 16/6/2026 | The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques. | |
| Modificada | Alta (7.5) | 1.6% | — | Checkpoint Check Point VPNCheckpoint Firewall-1Checkpoint Next Generation | 12/8/2002 | 16/6/2026 | Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file. | |
| Modificada | Alta (10) | 3.1% | — | Watchguard Soho Firewall | 12/8/2002 | 16/6/2026 | Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules. | |
| Modificada | Media (5) | 1.6% | — | Watchguard Soho Firewall | 12/8/2002 | 16/6/2026 | Watchguard SOHO firewall anteriores 5.0.35 permite a atacantes remotos provocar la Denegación de Servicios (caida y reinicio), cuando SOHO envía un paquete con las opciones IP erróneas. | |
| Modificada | Media (6.2) | 0.53% | — | Mandrakesoft Mandrake Single Network FirewallHP Secure OSMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 12/8/2002 | 16/6/2026 | setpwnam.c en el paquete util-linux, como se incluye en Red Hat Linux 7.3 y antieriores, y en otros sistemas operativos, no bloquea adecuadamente un fichero temporal cuando se modifica /etc/passwd, lo que puede permitir a usuarios locales ganar privilegios mediante una compleja condición de carrera que usa un… | |
| Modificada | Alta (7.5) | 3.3% | — | Symantec Norton Internet SecuritySymantec Norton Personal Firewall | 26/7/2002 | 16/6/2026 | Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request. | |
| Modificada | Alta (7.5) | 1.7% | — | Symantec Enterprise FirewallSymantec Raptor FirewallSymantec VelociraptorSymantec Gateway Security | 3/7/2002 | 16/6/2026 | FTP proxy in Symantec Raptor Firewall 6.5.3 and Enterprise 7.0 rewrites an FTP server's "FTP PORT" responses in a way that allows remote attackers to redirect FTP data connections to arbitrary ports, a variant of the "FTP bounce" vulnerability. | |
| Modificada | Media (4.6) | 0.40% | — | Tiny Software Tiny Personal Firewall | 25/6/2002 | 16/6/2026 | Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions. | |
| Modificada | Media (5) | 1.6% | — | Snapgear Lite+ Firewall | 18/6/2002 | 16/6/2026 | Snapgear Lite+ firewall 1.5.3 allows remote attackers to cause a denial of service (IPSEC crash) via a zero length packet to UDP port 500. | |
| Modificada | Media (5) | 1.6% | — | Snapgear Lite+ Firewall | 18/6/2002 | 16/6/2026 | Snapgear Lite+ firewall 1.5.3 and 1.5.4 allows remote attackers to cause a denial of service (crash) via a large number of packets with malformed IP options. | |
| Modificada | Media (5) | 1.9% | — | Snapgear Lite+ Firewall | 18/6/2002 | 16/6/2026 | Snapgear Lite+ firewall 1.5.4 and 1.5.3 allows remote attackers to cause a denial of service (crash) via a large number of connections to (1) the HTTP web management port, or (2) the PPTP port. | |
| Modificada | Media (5) | 1.3% | — | Symantec Enterprise Firewall | 31/5/2002 | 16/6/2026 | El demonio (daemon) de Symantec Enterprise Firewall 6.5.x deja caer importantes alertas cuando se usa SNMP como transporte, lo que podría impedir que algunas alertas se enviasen en caso de ataque. | |
| Modificada | Media (5) | 1.7% | — | Symantec Enterprise Firewall | 31/5/2002 | 16/6/2026 | El proxy SMTP en Symantec Enterprise Firewall 6.5.x incluye el nombre y la dirección del interfaz físico del cortafuegos en un intercambio de mensajes SMTP cuando la traduzzión NAT (network address translation) se hace a una dirección distinta de la del cortafuegos, lo que podría permitir a atacantes remotos… | |
| Modificada | Alta (7.2) | 0.34% | — | Checkpoint Firewall-1 | 1/4/2002 | 16/6/2026 | Chek Point Firewall-1 3.0b a 4.0 SP1 sigue enlaces simbólicos y crea un fichero temporal .cpp escribible por todos los usuarios cuando compila las reglas de seguridad, lo que permite a un usuario local obtener privilegios o modificar la política del web. | |
| Modificada | Crítica (9.8) | 15% | 💥 Exploit | ImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+7 | 15/3/2002 | 16/6/2026 | Error 'off-by-one' en el código de canal de OpenSSH 2.0 a 3.0.2 permite a usuarios locales o a servidores remotos ganar privilegios. | |
| Modificada | Baja (2.1) | 0.76% | 💥 Exploit | Tiny Software Tiny Personal Firewall | 31/12/2001 | 16/6/2026 | Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters. | |
| Modificada | Alta (7.5) | 7.8% | — | Apache Http ServerMandrakesoft Mandrake Single Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 28/11/2001 | 16/6/2026 | The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. | |
| Modificada | Baja (2.1) | 0.46% | — | Cisco PIX Firewall Manager | 10/10/2001 | 16/6/2026 | Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file. | |
| Modificada | Media (5) | 1.3% | — | Checkpoint Firewall-1Checkpoint Vpn-1Nokia Firewall Appliance | 8/10/2001 | 16/6/2026 | Nokia Firewall Appliances running IPSO 3.3 and VPN-1/FireWall-1 4.1 Service Pack 3, IPSO 3.4 and VPN-1/FireWall-1 4.1 Service Pack 4, and IPSO 3.4 or IPSO 3.4.1 and VPN-1/FireWall-1 4.1 Service Pack 5, when SYN Defender is configured in Active Gateway mode, does not properly rewrite the third packet of a TCP three-way… | |
| Modificada | Alta (7.5) | 3.9% | — | Checkpoint Firewall-1 | 21/9/2001 | 16/6/2026 | Buffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbitrary code via a long user name. | |
| Modificada | Media (6.2) | 0.30% | — | Checkpoint Firewall-1 | 8/9/2001 | 16/6/2026 | Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable. | |
| Modificada | Media (6.4) | 1.5% | — | Checkpoint Firewall-1 | 8/9/2001 | 16/6/2026 | The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Alta (7.5) | 5.7% | — | Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+1 | 4/9/2001 | 16/6/2026 | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | |
| Modificada | Media (5) | 1.3% | — | Checkpoint Firewall-1 | 31/8/2001 | 16/6/2026 | Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264. |