Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3074▲ 486 respecto a la semana anterior
Críticas / altas1457▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1847 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.9%—Barracuda Networks Barracuda Spam Firewall5/8/200616/6/2026
Login.pm en Barracuda Spam Firewall (BSF) 3.3.01.001 hasta la 3.3.03.053 contiene un cosntraseña fuertemente codificada para la cuenta de invitado, lo cual permite que atacantes remotos puedan leer información sensible como el log del e-mail, y posiblemente los contenidos del e-mail y la contraseña de admin.
ModificadaMedia (4)5.8%💥 ExploitBarracuda Networks Barracuda Spam Firewall5/8/200616/6/2026
Vulnerabilidad de salto de directorio en cgi-bin/preview_email.cgi en Barracuda Spam Firewall (BSF) 3.3.01.001 hasta la 3.3.03.053 permite a usuarios remotos validados leer archivos de su elección a través de la secuencia ..(punto punto) en el parámetro file.
ModificadaAlta (10)74%💥 ExploitEiqnetworks Enterprise Security Analyzer27/7/200616/6/2026
Múltiples desbordamientos de búfer basado en pila en eIQnetworks Enterprise Security Analyzer (ESA) anterior a 2.5.0, como se utiliza en productos que incluyen (a) SideWinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, y posiblemente…
ModificadaAlta (7.5)14%—Realnetworks Helix DNA Server28/6/200616/6/2026
Desbordamiento de búfer basado en memoria dinámica -heap- en RealNetworks Helix DNA Server v10.0 y v11.0 permite a atacantes remotos ejecutar código de su elección a través de (1)una cabecera larga HTTP User-Agent en el servicio RTSP y (2) vectores no especificados que incluyen "parsing of HTTP URL schemes".
ModificadaAlta (7.5)1.5%—IP3 Networks IP3 Netaccess 7526/4/200616/6/2026
na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has a default username of admin and a default password of admin.
ModificadaBaja (3.6)0.34%—IP3 Networks IP3 Netaccess 7526/4/200616/6/2026
The (1) shadow password file in na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 has world readable permissions, which allows local users to view encrypted passwords; and the (2) NetAccess database file has world readable and writable permissions, which allows local users to view sensitive information and modify…
ModificadaMedia (4.6)0.65%💥 ExploitIP3 Networks IP3 Netaccess 7526/4/200616/6/2026
na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).
ModificadaAlta (9.3)17%💥 ExploitRealnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody23/3/200616/6/2026
Desbordamiento de buffer en swfformat.dll en múltiples productos y versiones RealNetworks incluyendo RealPlayer 10.x, RealOne Player, Rhapsody 3 y Helix Player permite a atacantes remotos ejecutar código arbitrario a través de un archivo SWF (Flash) manipulado con (1) un valor de tamaño que es menor que el tamaño real…
ModificadaAlta (9.3)2.9%—Realnetworks Realone PlayerRealnetworks Realplayer23/3/200616/6/2026
Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.
ModificadaMedia (5)2.1%—UNU Networks Mailgust28/2/200616/6/2026
U.N.U. Mailgust 1.9 allows remote attackers to obtain sensitive information via a direct request to index.php with method=showfullcsv, which reveals the POP3 server configuration, including account name and password.
ModificadaAlta (9.3)5.8%—Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody31/12/200516/6/2026
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which…
ModificadaMedia (5)1.2%—SMC Networks Smc7904wbra31/12/200516/6/2026
SMC Wireless Router model SMC7904WBRA allows remote attackers to cause a denial of service (reboot) by flooding the router with traffic.
ModificadaMedia (5)1.4%—Inicom Networks Ioftpd31/12/200516/6/2026
ioFTPD 0.5.84 u responds with different messages depending on whether or not a username exists, which allows remote attackers to enumerate valid usernames.
ModificadaAlta (7.8)2.6%—Apani Networks Epiforce Agent17/12/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Apani Networks EpiForce 1.9 and earlier running IPSec, allow remote attackers to cause a denial of service (crash) via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is…
ModificadaAlta (7.5)1.8%—Realnetworks Realplayer9/12/200516/6/2026
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not…
ModificadaAlta (7.5)2.2%—Realnetworks Realplayer9/12/200516/6/2026
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows remote attackers to execute arbitrary code. NOTE: it is not known whether this issue should be MERGED with…
ModificadaAlta (7.5)3.3%—Realnetworks Realplayer18/11/200516/6/2026
Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different.
ModificadaMedia (5.1)13%💥 ExploitRealnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability…
ModificadaMedia (5.1)4.5%—Realnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094.
ModificadaAlta (7.2)3.3%—Realnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file.
ModificadaMedia (5.1)13%💥 ExploitRealnetworks Helix PlayerRealnetworks Realplayer27/9/200516/6/2026
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.
ModificadaAlta (7.5)1.2%💥 ExploitUNU Networks Mailgust27/9/200516/6/2026
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.
ModificadaMedia (5)8.8%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
ModificadaMedia (6.4)1.4%—Barracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
Argument injection vulnerability in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to (1) read portions of source code via the -f option to Dig (dig_device.cgi), (2) determine file existence via the -r argument to Tcpdump (tcpdump_device.cgi) or (3) modify files in the cgi-bin…
ModificadaAlta (7.5)53%💥 ExploitBarracuda Networks Barracuda Spam Firewall8/9/200516/6/2026
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.
Orbitaley — Vulnerabilidades