Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1807 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Alta (7.5) | 1.5% | — | Belkin 54G Wireless Router | 26/7/2005 | 16/6/2026 | Los rúter inalámbricos Belkin 54g no fijan adecuadamente el password de administración, lo que permite que atacantes remotos ganen acceso mediante las interfaces de administración de Telnet o de web. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 1.4% | — | Belkin 54G Wireless Router | 2/5/2005 | 16/6/2026 | Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication. | |
| Modificada | Alta (7.5) | 2.3% | — | Crosswire Bible Society Sword | 2/5/2005 | 16/6/2026 | diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |
| Modificada | Media (5) | 1.2% | — | Belkin 54G Wireless Router | 2/5/2005 | 16/6/2026 | The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 1.8% | — | Limewire | 14/3/2005 | 16/6/2026 | Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request. | |
| Modificada | Media (5) | 6.9% | 💥 Exploit | Limewire | 14/3/2005 | 16/6/2026 | LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. | |
| Modificada | Alta (7.2) | 0.48% | — | Firewire Ieee | 1/3/2005 | 16/6/2026 | A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degrees of physical access to exploit. NOTE: this was reported in… | |
| Modificada | Baja (2.1) | 0.33% | — | Checkpoint Check Point Integrity ClientZonelabs ZonealarmZonelabs Zonealarm Wireless Security | 11/2/2005 | 16/6/2026 | vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause… | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | IP3 Networks IP3 NetaccessIP3 Networks IP3 Netaccess - HospitalityIP3 Networks IP3 Netaccess - Wireless Hotspots | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34. | |
| Modificada | Alta (7.5) | 1.7% | — | Sweex Wireless Broadband Router Accesspoint 802.11g | 31/12/2004 | 16/6/2026 | Sweex Wireless Broadband Router/Accesspoint 802.11g (LC000060) allows remote attackers to obtain sensitive information and gain privileges by using TFTP to download the nvram file, then extracting the username, password, and other data from the file. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | 2wire Homeportal | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in wra/public/wralogin in 2Wire Gateway, possibly as used in HomePortal and other product lines, allows remote attackers to read arbitrary files via a .. (dot dot) in the return parameter. NOTE: this issue was reported as XSS, but this might be a terminology error. | |
| Modificada | Media (6.4) | 1.7% | — | Zonet Zsr1104we Wireless Router Runtime Code | 31/12/2004 | 16/6/2026 | The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions. | |
| Modificada | Media (5) | 15% | — | Microsoft Mn-500 Wireless Base Station | 6/12/2004 | 16/6/2026 | El interfaz de administración Web de Microsoft MN-500 Wireless Router permite a atacantes remotos causar una denegación de servicio (rechazo de conexión) mediante un número largo de conexiones HTTP. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | BT Voyager 2000 Wireless Adsl Router | 6/12/2004 | 16/6/2026 | El encaminador ADSL inalámbrico BT Voyager 2000 tiene un nombre de comunidad SNMP público por defecto, lo que permite a atacantes remotos obtener información sensible, como la contraseña, que se almacena en texto claro. | |
| Modificada | Alta (7.2) | 0.37% | — | Tripwire | 6/8/2004 | 16/6/2026 | Vulnerabildad de cadena de formato en Tripwire commercial 4.0.1 y anteriores, incluyendo 2.4, y open source 2.3.1 y anteriores permite a usuarios locales ganar privilegios mediante especificadores de cadena de formato en el nombre del ficheros, que es usado para la generación de un informe de correo electrónico. | |
| Modificada | Alta (7.5) | 1.5% | — | Wire Plastic Design Wpquiz | 30/7/2004 | 16/6/2026 | WpQuiz 2.60b1 through 2.60b8 allows remote attackers to gain privileges via a direct request to adminrestore.php in the extras directory. | |
| Modificada | Media (5) | 2.3% | — | Ieee 802.11 Wireless Protocol | 7/7/2004 | 16/6/2026 | El algoritmo de identificicación de canal vacio (Clear Channel Assessment - CCA) en el protocolo inalámbrico IEEE 802.11, cuando usa codificación de trasmisión de codificación DSSS, permite a atacantes remotos causar una denegación de servicio mediante ciertas señales de RF que causan que el canel aparezca ocupado… | |
| Modificada | Alta (10) | 4.6% | — | Cisco Wireless LAN Solution EngineCisco Hosting Solution Engine | 1/6/2004 | 16/6/2026 | Cisco Wireless LAN Solution Engine (WLSE) 2.0 through 2.5 and Hosting Solution Engine (HSE) 1.7 through 1.7.3 have a hardcoded username and password, which allows remote attackers to add new users, modify existing users, and change configuration. | |
| Modificada | Alta (7.5) | 3.8% | — | Nortel Business Communications ManagerNortel 802.11 Wireless IP GatewayNortel Succession Communication Server 1000 | 17/2/2004 | 16/6/2026 | Múltiples vulnerabilidades en la implementación del protocolo H.323 en Nortel Networks Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, y 802.11 Wireless IP Gateway permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario, como se demostró… | |
| Modificada | Media (4.6) | 1.3% | — | Microsoft Mn-500 Wireless Base Station | 31/12/2003 | 16/6/2026 | The backup configuration file for Microsoft MN-500 wireless base station stores administrative passwords in plaintext, which allows local users to gain access. | |
| Modificada | Media (5) | 1.6% | — | D-link Di-614+Longshine Technologie Longshine Wireless Ethernet Access Point | 31/12/2003 | 16/6/2026 | TFTP server in Longshine Wireless Access Point (WAP) LCS-883R-AC-B, and in D-Link DI-614+ 2.0 which is based on it, allows remote attackers to obtain the WEP secret and gain administrator privileges by downloading the configuration file (config.img) and other files without authentication. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Wireless Tools Project Wireless Tools | 15/12/2003 | 16/6/2026 | Desbordamiento de búfer en iwconfig (cuando tiene instalado un setuid ) permite que usuarios locales ejecuten código arbitrario mediante una variable de entorno OUT muy larga. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Wireless Tools | 15/12/2003 | 16/6/2026 | Desbordamiento de búfer en iwconfig permite que usuarios locales ejecuten código arbitrario mediante una variable de entorno HOME demasiado larga. |