Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | IBM Proventia Network Mail Security System FirmwareIBM Proventia Network Mail Security SystemIBM Lotus Protector FOR Mail Security | 20/7/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the administrative user interface in IBM Lotus Protector for Mail Security 2.1, 2.5, 2.5.1, and 2.8 and IBM ISS Proventia Network Mail Security System allow remote attackers to inject arbitrary web script or HTML via the query string. | |
| Modificada | Alta (9.3) | 5.1% | — | Symantec Mail SecuritySymantec Brightmail AND Messaging GatewaySymantec Data Loss Prevention | 18/7/2011 | 16/6/2026 | Buffer overflow in the Lotus Freelance Graphics PRZ file viewer in Autonomy KeyView, as used in Symantec Mail Security (SMS) 6.x through 8.x, Symantec Brightmail and Messaging Gateway before 9.5.1, and Symantec Data Loss Prevention (DLP) before 10.5.3 and 11.x before 11.1, allows remote attackers to cause a denial of… | |
| Modificada | Baja (3.5) | 0.70% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter. | |
| Modificada | Media (4) | 1.3% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Directory traversal vulnerability in sla/index.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the l parameter, related to an "Insecure Direct Object… | |
| Modificada | Media (6.8) | 0.52% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to hijack the authentication of administrators for requests that (1) change settings or (2) conduct… | |
| Modificada | Media (4.3) | 0.86% | — | IBM Proventia Network Mail Security System Virtual ApplianceIBM Proventia Network Mail Security System Virtual Appliance Firmware | 14/9/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via (1) the date1 parameter to pvm_messagestore.php, (2) the… | |
| Modificada | Alta (9.3) | 4.1% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKSymantec Mail Security | 17/8/2010 | 16/6/2026 | Stack-based buffer overflow in the SpreadSheet Lotus 123 reader (wkssr.dll), as used in Autonomy KeyView 10.4 and 10.9, Symantec Mail Security, and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to floating point conversion in unknown record types. | |
| Modificada | Alta (10) | 3.7% | — | IBM Lotus NotesSymantec Brightmail GatewaySymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+2 | 5/3/2010 | 16/6/2026 | Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a… | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Websense Email SecurityWebsense Personal Email Manager | 22/10/2009 | 16/6/2026 | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Websense Personal Email ManagerWebsense Email Security | 22/10/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5)… | |
| Modificada | Alta (9.3) | 5.7% | — | IBM Lotus NotesSymantec Brightmail ApplianceSymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+3 | 1/9/2009 | 16/6/2026 | Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls… | |
| Modificada | Alta (10) | 2.3% | — | IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Proventia Network Mail Security System Vitual ApplianceIBM Proventia Network Multi-function Security | 20/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Ironport AsyncosCisco Ironport Email Security Appliances | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter. | |
| Modificada | Alta (10) | 2.7% | — | IBM Proventia Desktop Endpoint SecurityIBM Proventia Network Mail Security SystemIBM Network Multi-function SecurityIBM Proventia Network Mail Security System Virtual Appliance | 3/4/2009 | 16/6/2026 | Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of… | |
| Modificada | Alta (9.3) | 6.8% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes+6 | 18/3/2009 | 16/6/2026 | Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Sonicwall E-mail Security | 12/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page. | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a… | |
| Modificada | Alta (9.3) | 3.0% | — | IBM Lotus NotesSymantec Mail SecurityAutonomy Keyview | 10/4/2008 | 16/6/2026 | kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a… | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3)… | |
| Modificada | Alta (7.1) | 2.6% | — | Symantec Scan EngineSymantec Antivirus ClearswiftSymantec Antivirus Filtering Domino MPESymantec Antivirus Messaging+6 | 28/2/2008 | 16/6/2026 | Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp). | |
| Modificada | Media (6.8) | 3.7% | — | Symantec Scan EngineSymantec Antivirus Filtering Domino MPESymantec Antivirus Network Attached StorageSymantec Antivirus Scan Engine+6 | 28/2/2008 | 16/6/2026 | Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content… | |
| Modificada | Alta (9.3) | 6.6% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect… | |
| Modificada | Alta (9.3) | 21% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to… | |
| Modificada | Alta (9.3) | 6.0% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives. | |
| Modificada | Alta (9.3) | 3.9% | — | Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+9 | 5/10/2007 | 16/6/2026 | The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header. |