Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

281 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9)52%💥 ExploitBroadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupCA Brightstor Arcserve BackupCA Threat Manager FOR THE Enterprise7/4/200816/6/2026
Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to…
ModificadaMedia (6.8)3.6%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+820/3/200816/6/2026
Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as…
ModificadaAlta (7.5)2.5%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+422/2/200816/6/2026
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792.
ModificadaMedia (5.8)2.2%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus FOR LinuxF-secure Anti-virus FOR Workstations+415/2/200816/6/2026
Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.
ModificadaAlta (10)7.9%—Clam Anti-virus Clamav12/2/200816/6/2026
Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.
ModificadaMedia (5)2.3%—Clam Anti-virus Clamav31/12/200716/6/2026
ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows remote attackers to bypass the scanner via a Base64-UUEncoded file.
ModificadaBaja (2.1)0.41%—Clam Anti-virus Clamav31/12/200716/6/2026
ClamAV 0.92 allows local users to overwrite arbitrary files via a symlink attack on (1) temporary files used by the cli_gentempfd function in libclamav/others.c or on (2) .ascii files used by sigtool, when utf16-decode is enabled.
ModificadaAlta (10)2.8%—Clam Anti-virus Clamav31/12/200716/6/2026
Unspecified vulnerability in the bzip2 decompression algorithm in nsis/bzlib_private.h in ClamAV before 0.92 has unknown impact and remote attack vectors.
ModificadaMedia (6.8)4.2%—Clam Anti-virus Clamav20/12/200716/6/2026
Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.
ModificadaAlta (7.5)18%💥 ExploitClam Anti-virus Clamav20/12/200716/6/2026
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which triggers a heap-based buffer overflow.
ModificadaAlta (9.3)8.1%💥 ExploitBitdefender Online Anti-virus Scanner30/11/200716/6/2026
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remote attackers to execute arbitrary code via a long argument to the InitX method that begins with a "%%" sequence, which is misinterpreted as a Unicode string and decoded twice, leading to improper…
ModificadaAlta (7.5)2.6%—Clam Anti-virus Clamav20/11/200716/6/2026
Unspecified vulnerability in ClamAV 0.91.1 and 0.91.2 allows remote attackers to execute arbitrary code via a crafted e-mail message. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has…
ModificadaBaja (1.9)0.30%—F-secure Anti-virus1/10/200716/6/2026
F-Secure Anti-Virus for Windows Servers 7.0 64-bit edition allows local users to bypass virus scanning by using the system32 directory to store a crafted (1) archive or (2) packed executable. NOTE: in many environments, this does not cross privilege boundaries because any process able to write to system32 could also…
ModificadaBaja (2.1)0.44%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security26/9/200716/6/2026
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4)…
ModificadaMedia (5)5.7%—Sophos Scanning EngineSophos Anti-virus10/9/200716/6/2026
The virus detection engine in Sophos Anti-Virus before 2.49.0 does not properly process malformed (1) CAB, (2) LZH, and (3) RAR files with modified headers, which might allow remote attackers to bypass malware detection.
ModificadaMedia (4.3)4.8%—Sophos Anti-virus10/9/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in…
ModificadaAlta (7.2)0.89%💥 ExploitMicroworld Technologies Escan Anti-virusMicroworld Technologies Escan Internet SecurityMicroworld Technologies Escan Virus Control31/8/200716/6/2026
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
ModificadaMedia (6.8)7.3%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Windows and for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted UPX packed file, resulting from an "integer cast around". NOTE: as of 20070828, the vendor says this is a DoS and the researcher says this allows…
ModificadaAlta (7.8)5.5%—Sophos Anti-virusSophos Scanning EngineSophos Small Business Suite28/8/200716/6/2026
Sophos Anti-Virus for Unix/Linux before 2.48.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed BZip file that results in the creation of multiple Engine temporary files (aka a "BZip bomb").
ModificadaAlta (7.6)84%💥 ExploitClam Anti-virus Clamav28/8/200716/6/2026
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
ModificadaMedia (4.3)2.0%—Clam Anti-virus ClamavKolab Server23/8/200716/6/2026
ClamAV before 0.91.2, as used in Kolab Server 2.0 through 2.2beta1 and other products, allows remote attackers to cause a denial of service (application crash) via (1) a crafted RTF file, which triggers a NULL dereference in the cli_scanrtf function in libclamav/rtf.c; or (2) a crafted HTML document with a data: URI,…
ModificadaMedia (4.3)3.6%—Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+1926/7/200716/6/2026
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
ModificadaMedia (5)1.9%—Kaspersky LAB Kaspersky Anti-virus 5.5 FOR Check Point Firewall-19/7/200716/6/2026
Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.
ModificadaAlta (9.3)14%—Broadcom Alert Notification ServerBroadcom Brightstor Arcserve BackupBroadcom Brightstor Enterprise BackupCA Anti-virus FOR THE Enterprise+418/7/200716/6/2026
Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve products, and BrightStor Enterprise Backup, allow remote attackers…
ModificadaMedia (4.3)7.7%💥 ExploitClam Anti-virus Clamav12/7/200716/6/2026
The RAR VM (unrarvm.c) in Clam Antivirus (ClamAV) before 0.91 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive, resulting in a NULL pointer dereference.
Orbitaley — Vulnerabilidades