Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3085▲ 506 respecto a la semana anterior
Críticas / altas1460▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1918 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (5) | 1.2% | — | Information Call Center | 21/12/2005 | 16/6/2026 | Information Call Center stores the CallCenterData.mdb database under the web root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords. | |
| Modificada | Alta (7.8) | 87% | 💥 Exploit | Microsoft Internet Information Services | 20/12/2005 | 16/6/2026 | The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to produce a return value that is not correctly handled by IIS, as… | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | Amax Information Technologies Magic Winmail Server | 25/11/2005 | 16/6/2026 | Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter. | |
| Modificada | Media (4.3) | 2.1% | — | Amax Information Technologies Magic Winmail Server | 19/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlogin.php, (2) Content-Type headers in HTML mails, and (3) HTML mail attachments. | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Media (5) | 42% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 23/8/2005 | 16/6/2026 | Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost. | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Media (4.3) | 31% | — | Microsoft Internet Information Services | 5/7/2005 | 16/6/2026 | Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to incorrectly handle and forward the body of the request in a… | |
| Modificada | Alta (7.5) | 1.6% | — | Stackworks Enterprises Information Resource Manager | 14/3/2005 | 16/6/2026 | Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins. | |
| Modificada | Media (4.6) | 0.75% | — | Amax Information Technologies Magic Winmail Server | 27/1/2005 | 16/6/2026 | The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning. | |
| Modificada | Alta (7.5) | 3.4% | 💥 Exploit | Amax Information Technologies Magic Winmail Server | 27/1/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files via certain parameters to upload.php or (2) read arbitrary files via certain parameters to download.php, and remote authenticated users to read, create, or delete arbitrary… | |
| Modificada | Alta (10) | 6.0% | — | Dxfscope DXF File Format Viewer | 10/1/2005 | 16/6/2026 | Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file. | |
| Modificada | Baja (3.6) | 0.63% | 💥 Exploit | Mtools Mformat | 31/12/2004 | 16/6/2026 | MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files. | |
| Modificada | Media (5) | 1.7% | — | Amax Information Technologies Magic Winmail Server | 31/12/2004 | 16/6/2026 | AMAX Magic Winmail Server 3.6 allows remote attackers to obtain sensitive information by entering (1) invalid characters such as "()" or (2) a large number of characters in the Lookup field on the netaddressbook.php web form, which reveals the path in an ldaplib.php error message when the ldap_search function fails,… | |
| Modificada | Baja (2.1) | 0.30% | — | SUN Storedge QFSSUN Storedge Sam-qfsSUN Storeedge Performance SuiteSUN Storeedge Utilization Suite | 31/12/2004 | 16/6/2026 | Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files. | |
| Modificada | Media (5) | 88% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 3/11/2004 | 16/6/2026 | El Manejador de Mensajes WebDAV de Internet Information Server (IIS) 5.0, 5.1, y 6.0 permite a atacantes remotos causar una denegación de servicio (consumición de memoria y CPU), caída de aplicación mediante un mensaje XML conteniendo elementos XML con un gran número de atributos. | |
| Modificada | Alta (7.2) | 24% | — | Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en Microsoft Internet Information Server (IIS) 4.0 permite a usuarios locales ejecutar código de su elección mediante la función de redirección. | |
| Modificada | Alta (7.5) | 3.5% | 💥 Exploit | Amax Information Technologies Magic Winmail Server | 2/7/2003 | 16/6/2026 | Vulnerabilidad de cadena de formato en Magic WinMail Server 2.3, y posiblemente otras versiones 2.x, permite a atacantes remotos causar una denegación de servicio (caída) y posiblemente ejecutar código arbitrario mediante especificadores de cadena de formato en el comando PASS. | |
| Modificada | Media (5) | 38% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 9/6/2003 | 16/6/2026 | La función ASP Response.AddHeader en Microsoft Internet Information Server (IIS) 4.0 y 5.0 no limita peticiones de memoria cuando se construyen los encabezamientos, lo que permite que atacantes remotos generen un encabezamiento largo que causa una denegación de servicio (agotamiento de memoria) con una página ASP. | |
| Modificada | Media (6.8) | 17% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 9/6/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en la función ASP responsable de la redirección en el Microsoft Internet Information Server (IIS) 4.0, 5.0, y 5.1 permite que atacantes remotos embeban una URL que contiene script en un mensaje de redirección. | |
| Modificada | Media (5) | 43% | 💥 Exploit | Microsoft Internet Information Services | 9/6/2003 | 16/6/2026 | Microsoft Internet Information Services (IIS) 5.0 y 5.1 permite que atacantes remotos provoquen una denegación de servicio vía una petición WebDav muy larga con los métodos PROPFIND o SEARCH, lo que genera una condición de error que no se está manejando apropiadamente. | |
| Modificada | Alta (10) | 18% | — | Microsoft Internet Information Services | 9/6/2003 | 16/6/2026 | Desbordamiento de búfer en la componente que sirve páginas web estáticas en Microsoft Internet Information Services (IIS) 5.0 permite que atacantes remotos ejecuten código arbitrario con permisos de nivel usuario mediante un página web SHTML. | |
| Modificada | Media (5) | 34% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Internet Information ServerMicrosoft Internet Information Services | 31/12/2002 | 16/6/2026 | The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682. |