Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Symantec Endpoint Protection ManagerSymantec Protection Center | 14/2/2014 | 16/6/2026 | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in… | |
| Modificada | Alta (7.2) | 0.47% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory. | |
| Modificada | Media (4.6) | 0.35% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | The Application/Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly handle custom polices, which allows local users to bypass intended policy… | |
| Modificada | Alta (7.4) | 0.78% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin… | |
| Modificada | Alta (7.9) | 4.4% | 💥 Exploit | Symantec Endpoint Protection ManagerSymantec Endpoint Protection Center | 20/6/2013 | 16/6/2026 | Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.2% | — | Symantec Endpoint Protection | 18/12/2012 | 16/6/2026 | The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec AntivirusSymantec Endpoint ProtectionSymantec Scan Engine | 14/11/2012 | 16/6/2026 | The decomposer engine in Symantec Endpoint Protection (SEP) 11.0, Symantec Endpoint Protection Small Business Edition 12.0, Symantec AntiVirus Corporate Edition (SAVCE) 10.x, and Symantec Scan Engine (SSE) before 5.2.8 does not properly perform bounds checks of the contents of CAB archives, which allows remote… | |
| Modificada | Media (5) | 1.2% | — | Mcafee Saas Endpoint Protection | 22/8/2012 | 16/6/2026 | The Rumor technology in McAfee SaaS Endpoint Protection before 5.2.4 allows remote attackers to relay e-mail messages via unspecified vectors, as demonstrated by relaying spam. | |
| Modificada | Media (5) | 2.8% | — | Symantec Endpoint Protection | 24/5/2012 | 16/6/2026 | The Network Threat Protection module in the Manager component in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.700x on Windows Server 2003 allows remote attackers to cause a denial of service (web-server outage, or daemon crash or hang) via a flood of packets that triggers automated blocking of network… | |
| Modificada | Alta (9.3) | 4.0% | — | Symantec Endpoint Protection | 23/5/2012 | 16/6/2026 | The Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to conduct file-insertion attacks and execute arbitrary code by leveraging exploitation of CVE-2012-0294. | |
| Modificada | Media (5.8) | 1.6% | — | Symantec Endpoint Protection | 23/5/2012 | 16/6/2026 | Directory traversal vulnerability in the Manager service in the management console in Symantec Endpoint Protection (SEP) 12.1 before 12.1 RU1-MP1 allows remote attackers to delete files via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.5% | 💥 Exploit | Symantec Endpoint ProtectionSymantec Network Access Control | 23/5/2012 | 16/6/2026 | Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.710x allows local users to gain privileges, and modify data or cause a denial of service, via a crafted script. | |
| Modificada | Media (4.3) | 98% | — | Ahnlab V3 Internet SecurityAladdin EsafeAVG Anti-virusCAT Quick Heal+6 | 21/3/2012 | 16/6/2026 | The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus… | |
| Modificada | Media (4.3) | 92% | — | Anti-virus Vba32Authentium Command AntivirusAVG Anti-virusBitdefender+16 | 21/3/2012 | 16/6/2026 | The Gzip file parser in AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Secure Anti-Virus 9.0.16160.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, K7 AntiVirus 9.77.3565, Kaspersky… | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+30 | 21/3/2012 | 16/6/2026 | The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Comodo Antivirus 7424,… | |
| Modificada | Media (4.3) | 98% | — | Aladdin EsafeAlwil Avast AntivirusAnti-virus Vba32Antiy AVL SDK+24 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus… | |
| Modificada | Media (4.3) | 100% | — | Aladdin EsafeAVG Anti-virusCAT Quick HealComodo Antivirus+16 | 21/3/2012 | 16/6/2026 | The TAR file parser in AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Comodo Antivirus 7424, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky… | |
| Modificada | Media (4.3) | 100% | — | Aladdin EsafeAntiy AVL SDKCA Etrust VET AntivirusCAT Quick Heal+10 | 21/3/2012 | 16/6/2026 | The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (formerly Webwasher) 2010.1C, Sophos Anti-Virus 4.61.0, CA… | |
| Modificada | Media (4.3) | 100% | — | Ahnlab V3 Internet SecurityAladdin EsafeAlwil Avast AntivirusAnti-virus Vba32+31 | 21/3/2012 | 16/6/2026 | The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Emsisoft Anti-Malware 5.1.0.1, PC Tools… | |
| Modificada | Media (4.3) | 93% | — | Antiy AVL SDKAvira AntivirCAT Quick HealEmsisoft Anti-malware+12 | 21/3/2012 | 16/6/2026 | The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, Jiangmin Antivirus 13.0.900, Kaspersky Anti-Virus 7.0.0.125, McAfee Anti-Virus… | |
| Modificada | Media (4.3) | 89% | — | CAT Quick HealNorman Antivirus & AntispywareRising-global Rising AntivirusSymantec Endpoint Protection | 21/3/2012 | 16/6/2026 | The TAR file parser in Quick Heal (aka Cat QuickHeal) 11.00, Norman Antivirus 6.06.12, Rising Antivirus 22.83.00.03, and AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11 allows remote attackers to bypass malware detection via a POSIX TAR file with an initial MSCF character sequence. NOTE: this may later be… | |
| Modificada | Media (6.8) | 0.64% | — | Symantec Endpoint Protection | 15/8/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts. | |
| Modificada | Media (4.3) | 1.3% | — | Symantec Endpoint Protection | 15/8/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Interface in the Endpoint Protection Manager in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.6300 allow remote attackers to inject arbitrary web script or HTML via (1) the token parameter to portal/Help.jsp or (2) the URI in a… | |
| Modificada | Media (6.8) | 1.2% | — | Mcafee Saas Endpoint Protection | 10/8/2011 | 16/6/2026 | The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the… | |
| Modificada | Media (6.8) | 2.1% | — | Mcafee Saas Endpoint Protection | 10/8/2011 | 16/6/2026 | The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the… |