Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2886▲ 263 respecto a la semana anterior
Críticas / altas1344▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1837 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.2% | — | Ktools | 29/11/2005 | 16/6/2026 | Stack-based buffer overflow in kkstrtext.h in ktools library 0.3 and earlier, as used in products such as (1) centericq, (2) orpheus, (3) motor, and (4) groan, allows local users or remote attackers to execute arbitrary code via a long parameter to the VGETSTRING macro. | |
| Modificada | Alta (7.5) | 1.2% | — | Onlinetechtools.com Owos Lite | 27/11/2005 | 16/6/2026 | SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Okbsys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Onlinetechtools.com Oasys Lite | 27/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter. | |
| Modificada | Alta (7.8) | 4.4% | — | Ipsec-tools | 21/11/2005 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in racoon in ipsec-tools before 0.6.3, when running in aggressive mode, allows remote attackers to cause a denial of service (null dereference and crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. | |
| Modificada | Alta (10) | 3.0% | — | Oracle PeopletoolsAIOracle Peoplesoft EnterpriseAI | 2/11/2005 | 16/6/2026 | Vulnerabilidad no especificada en PeopleTools en Oracle PeopleSoft Enterprise 8.42 hasta la versión 8.45.17 tiene impacto y vectores de ataque no especificados, según lo identificado por Oracle Vuln# PSE01. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 2.1% | — | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename. | |
| Modificada | Baja (2.1) | 0.33% | — | Mpeg-tools | 30/9/2005 | 16/6/2026 | mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN]. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 1.1% | — | Opentools Attachment MOD | 17/5/2005 | 16/6/2026 | Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors. | |
| Modificada | Baja (2.1) | 0.31% | — | Cdrtools Cdrecord | 2/5/2005 | 16/6/2026 | cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Media (5) | 2.4% | — | Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+3 | 14/3/2005 | 16/6/2026 | The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Michael Kohn Ringtonetools | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en la función parse_emelody en parse_emelody.c de ringtonetools 2.22 permite a atacantes ejecutar código de su elección mediante un fichero eMelody artesanal. | |
| Modificada | Alta (7.2) | 1.7% | 💥 Exploit | Cdrtools Cdrecord | 31/12/2004 | 16/6/2026 | cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges. | |
| Modificada | Media (5) | 1.9% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in frmGetAttachment.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to read arbitrary files via the filename parameter. | |
| Modificada | Media (4) | 1.1% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | frmAddfolder.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote authenticated users to create a folder that SmarterMail cannot delete or rename via a folder name with a null byte ("%00"). NOTE: it is not clear whether this issue poses a vulnerability. | |
| Modificada | Baja (3.6) | 0.63% | 💥 Exploit | Mtools Mformat | 31/12/2004 | 16/6/2026 | MTools Mformat before 3.9.9, when installed setuid root, creates files with world-readable and world-writable permissions, which allows local users to read and overwrite files. | |
| Modificada | Media (4.3) | 1.4% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in frmCompose.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to inject arbitrary web script or HTML via Javascript to the "check spelling" feature in the compose area. | |
| Modificada | Alta (7.5) | 2.9% | — | Opentools Attachment MOD | 31/12/2004 | 16/6/2026 | Attachment Mod 2.3.10 module for phpBB, when used with Apache mod_mime, does not properly handle files with multiple file extensions, such as .php.rar, which allows remote attackers to upload and execute arbitrary code. | |
| Modificada | Media (4.6) | 1.5% | — | Microsoft PsexecMicrosoft PsgetsidMicrosoft PsinfoMicrosoft Pskill+7 | 31/12/2004 | 16/6/2026 | Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not… | |
| Modificada | Alta (7.8) | 1.8% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25. | |
| Modificada | Media (5) | 1.7% | — | Opentools Attachment MOD | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in the Attachment module 2.3.10 and earlier for phpBB allows remote attackers to read arbitrary files via a .. (dot dot) in the filename. | |
| Modificada | Media (5) | 1.9% | — | Smartertools Smartermail | 31/12/2004 | 16/6/2026 | login.aspx in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service via a long txtusername parameter, possibly due to a buffer overflow. | |
| Modificada | Alta (10) | 5.4% | — | Ipsec-toolsKame RacoonRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 6/12/2004 | 16/6/2026 | La función eay_check_x509cert en KAME Racoon verifica como buenos certificados incluso cuando la validación OpenSLL falla, lo que podría permitir a atacantes remotos saltarse la autenticación. |