Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

1918 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)19%—Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+3031/12/200516/6/2026
Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.
ModificadaMedia (5)1.2%—Information Call Center21/12/200516/6/2026
Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.
ModificadaAlta (7.8)87%💥 ExploitMicrosoft Internet Information Services20/12/200516/6/2026
The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as…
ModificadaMedia (5)7.3%💥 ExploitAmax Information Technologies Magic Winmail Server25/11/200516/6/2026
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.
ModificadaMedia (4.3)2.1%—Amax Information Technologies Magic Winmail Server19/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments.
ModificadaAlta (10)7.3%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.
ModificadaMedia (5)42%—Microsoft Internet Information ServerMicrosoft Internet Information Services23/8/200516/6/2026
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.
ModificadaAlta (10)75%💥 ExploitBroadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2423/8/200516/6/2026
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5)3.1%—Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+2023/8/200516/6/2026
Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability."
ModificadaMedia (4.3)31%—Microsoft Internet Information Services5/7/200516/6/2026
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a…
ModificadaAlta (7.5)1.6%—Stackworks Enterprises Information Resource Manager14/3/200516/6/2026
Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.
ModificadaMedia (4.6)0.75%—Amax Information Technologies Magic Winmail Server27/1/200516/6/2026
The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.
ModificadaAlta (7.5)3.4%💥 ExploitAmax Information Technologies Magic Winmail Server27/1/200516/6/2026
Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary…
ModificadaAlta (10)6.0%—Dxfscope DXF File Format Viewer10/1/200516/6/2026
Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file.
ModificadaBaja (3.6)0.63%💥 ExploitMtools Mformat31/12/200416/6/2026
MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files.
ModificadaMedia (5)1.7%—Amax Information Technologies Magic Winmail Server31/12/200416/6/2026
AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails,…
ModificadaBaja (2.1)0.30%—SUN Storedge QFSSUN Storedge Sam-qfsSUN Storeedge Performance SuiteSUN Storeedge Utilization Suite31/12/200416/6/2026
Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.
ModificadaMedia (5)88%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services3/11/200416/6/2026
El Manejador de Mensajes WebDAV de Internet Information Server (IIS) 5.0, 5.1, y 6.0 permite a atacantes remotos causar una denegación de servicio (consumición de memoria y CPU), caída de aplicación mediante un mensaje XML conteniendo elementos XML con un gran número de atributos.
ModificadaAlta (7.2)24%—Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+16/8/200416/6/2026
Desbordamiento de búfer en Microsoft Internet Information Server (IIS) 4.0 permite a usuarios locales ejecutar código de su elección mediante la función de redirección.
ModificadaAlta (7.5)3.5%💥 ExploitAmax Information Technologies Magic Winmail Server2/7/200316/6/2026
Vulnerabilidad de cadena de formato en Magic WinMail Server 2.3, y posiblemente otras versiones 2.x, permite a atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario mediante especificadores de cadena de formato en el comando PASS.
ModificadaMedia (5)38%—Microsoft Internet Information ServerMicrosoft Internet Information Services9/6/200316/6/2026
La función ASP Response.AddHeader en Microsoft Internet Information Server (IIS) 4.0 y 5.0 no limita peticiones de memoria cuando se construyen los encabezamientos, lo que permite que atacantes remotos generen un encabezamiento largo que causa una denegación de servicio (agotamiento de memoria) con una página ASP.
ModificadaMedia (6.8)17%—Microsoft Internet Information ServerMicrosoft Internet Information Services9/6/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en la función ASP responsable de la redirección en el Microsoft Internet Information Server (IIS) 4.0, 5.0, y 5.1 permite que atacantes remotos embeban una URL que contiene script en un mensaje de redirección.
ModificadaMedia (5)43%💥 ExploitMicrosoft Internet Information Services9/6/200316/6/2026
Microsoft Internet Information Services (IIS) 5.0 y 5.1 permite que atacantes remotos provoquen una denegación de servicio vía una petición WebDav muy larga con los métodos PROPFIND o SEARCH, lo que genera una condición de error que no se está manejando apropiadamente.
ModificadaAlta (10)18%—Microsoft Internet Information Services9/6/200316/6/2026
Desbordamiento de búfer en la componente que sirve páginas web estáticas en Microsoft Internet Information Services (IIS) 5.0 permite que atacantes remotos ejecuten código arbitrario con permisos de nivel usuario mediante un página web SHTML.
ModificadaMedia (5)34%💥 ExploitMicrosoft Exchange ServerMicrosoft Internet Information ServerMicrosoft Internet Information Services31/12/200216/6/2026
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
Orbitaley — Vulnerabilidades