Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1895 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.2% | — | Oracle Client | 4/2/2006 | 16/6/2026 | Buffer overflow in an unspecified Oracle Client utility might allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: due to the lack of relevant details from the Oracle advisory, a separate CVE is being created since it cannot be conclusively proven that this issue has been addressed by… | |
| Modificada | Alta (7.2) | 0.36% | — | AOL Client Software | 2/2/2006 | 16/6/2026 | The default configuration of the America Online (AOL) client software allows all users to modify a certain registry value that specifies a DLL file name, which might allow local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (5) | 1.2% | — | Zbattle.net Zbattle Client | 1/2/2006 | 16/6/2026 | zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game. | |
| Modificada | Alta (10) | 10% | — | AOL Client Software | 19/1/2006 | 16/6/2026 | Buffer overflow in YGPPicFinder.DLL in AOL You've Got Pictures (YGP) Picture Finder Tool ActiveX Control, as used in AOL 8.0, 8.0 Plus, and 9.0 Classic, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | Clientexec | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters. | |
| Modificada | Alta (7.8) | 1.8% | — | Fortinet FortiosAIFortinet ForticlientAIFortinet FortimanagerAI | 29/12/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restarted) via IKE packets with invalid values of certain IPSec… | |
| Modificada | Alta (7.5) | 2.6% | — | Cisco VPN 3001 ConcentratorCisco VPN 3015 ConcentratorCisco VPN 3020 ConcentratorCisco VPN 3030 Concentator+17 | 22/12/2005 | 16/6/2026 | The Downloadable RADIUS ACLs feature in Cisco PIX and VPN 3000 concentrators, when creating an ACL on the Cisco Secure Access Control Server (CS ACS), generates a random internal name for an ACL that is also used as a hidden user name and password, which allows remote attackers to gain privileges by sniffing the… | |
| Modificada | Baja (2.1) | 0.44% | — | Citrix Program Neighborhood Client | 20/12/2005 | 16/6/2026 | Citrix Program Neighborhood client before 9.150 caches the user password in plaintext in the GUI while asterisks are used to visually obfuscate the password, which allows attackers with access to the session to obtain the password by using a tool to directly access the field. | |
| Modificada | Media (4.3) | 1.4% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to inject arbitrary web script or HTML via the (1) Schedule… | |
| Modificada | Alta (7.8) | 2.0% | — | Hitachi Cosminexus Collaboration PortalHitachi Groupmax Collaboration PortalHitachi Groupmax Collaboration WEB Client | 17/12/2005 | 16/6/2026 | Unspecified vulnerability in Hitachi Cosminexus Collaboration Portal 06-00 through 06-10-/B, Groupmax Collaboration Portal 07-00 through 07-10-/B, and Groupmax Collaboration Web Client 07-00 through 07-10-/A allow remote attackers to cause a denial of service of unspecified impact via repeated invalid requests to the… | |
| Modificada | Alta (7.5) | 16% | — | Citrix ICA Program Neighborhood Client | 16/12/2005 | 16/6/2026 | Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response. | |
| Modificada | Alta (7.5) | 1.3% | — | Alt-n MdaemonAlt-n Worldclient | 15/12/2005 | 16/6/2026 | WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Alt-n MdaemonAlt-n Worldclient | 13/12/2005 | 16/6/2026 | WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Checkpoint Secureclient NGCheckpoint Vpn-1 Secureclient | 8/12/2005 | 16/6/2026 | Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Alta (10) | 60% | 💥 Exploit | Symantec Veritas Netbackup Data AND Business CenterSymantec Veritas Netbackup Enterprise Server Client | 12/10/2005 | 16/6/2026 | Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command. | |
| Modificada | Baja (2.1) | 0.40% | — | Linecontrol Java Client | 20/9/2005 | 16/6/2026 | AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files. | |
| Modificada | Alta (7.2) | 0.39% | — | AOL Client Software | 17/8/2005 | 16/6/2026 | AOL Client Software 9.0 uses insecure permissions for its installation path, which allows local users to execute arbitrary code with SYSTEM privileges by replacing ACSD.exe with a malicious program. | |
| Modificada | Media (5) | 17% | — | Microsoft Telnet ClientMIT Kerberos 5Sunos | 14/6/2005 | 16/6/2026 | Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. | |
| Modificada | Media (4.6) | 0.92% | 💥 Exploit | Altiris Client ServiceAltiris Deployment Solution | 16/5/2005 | 16/6/2026 | The Altiris Client Service for Windows (ACLIENT.EXE) 6.0.88 allows local users to disable password protection and access the administrative interface by finding and showing the "Altiris Client Service" hidden window, disabling the password protection, disabling the "Hide client tray icon box" option, then opening the… | |
| Modificada | Alta (7.5) | 62% | — | HP Radia Client | 3/5/2005 | 16/6/2026 | Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process. | |
| Modificada | Alta (7.5) | 8.4% | — | HP Radia Client | 3/5/2005 | 16/6/2026 | Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension. | |
| Modificada | Baja (2.1) | 0.44% | — | Safenet Softremote VPN Client | 2/5/2005 | 16/6/2026 | SafeNet SoftRemote VPN Client stores the VPN password (pre-shared key) in cleartext in memory of the IreIKE.exe process, which allows local users to gain sensitive information if they have access to that process. | |
| Modificada | Alta (7.5) | 4.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+11 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure. | |
| Modificada | Alta (7.5) | 2.2% | — | Centrinity Firstclass Desktop Client | 2/5/2005 | 16/6/2026 | OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. |