Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3145▲ 569 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
1847 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 74% | 💥 Exploit | Mcafee Epolicy OrchestratorMcafee Protectionpilot | 5/10/2006 | 16/6/2026 | Desbordamiento de búfer en McAfee ePolicy Orchestrator anterior a 3.5.0.720 y ProtectionPilot anterior a 1.1.1.126 permite a atacantes remotos ejecutar código de su elección mediante una petición a /spipe/pkg/ con una cabecera fuente larga. | |
| Modificada | Media (4.6) | 0.73% | 💥 Exploit | ISS Blackice PC Protection | 5/9/2006 | 16/6/2026 | RapDrv.sys en BlackICE PC Protection 3.6.cpn, cpj, cpiE, y posiblemente 3.6 y anteriores, permite a usuarios locales provocar denegación de servicio (caida) a través de un tercer argumento NULL a la función NtOpenSection API. NOTA: Posteriormente fue notificado que 3.6.cqn también se ve afectado. | |
| Modificada | Alta (7.5) | 10% | — | HP Openview Storage Data Protector | 17/8/2006 | 16/6/2026 | Vulnerabilidad no especificada en el agente de copia de respaldo (backup agent) y el Cell Manager de HP OpenView Storage Data Protector 5.1 y 5.5 anteiror al 10/08/2006 permite a atacantes remotos ejecutar código de su elección en un agente a través de vectores no especificados relacionados con la autenticación y la… | |
| Modificada | Media (4.6) | 0.33% | — | ISS Blackice PC Protection | 5/8/2006 | 16/6/2026 | ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, y posiblemente anteriores versiones no monitorizan adecuadamente la integridad de la libreria pamversion.dll BlackICE, lo caul permite a un usuario local "trastornar" BlackICE a través del remplazo de pamversion.dll. NOTA: en la mayoría de los casos, el ataque no cruzaría… | |
| Modificada | Baja (2.1) | 0.23% | — | Symantec On-demand AgentSymantec On-demand Protection | 5/8/2006 | 16/6/2026 | Symantec On-Demand Agent (SODA) anterior a 2.5 MR2 Build 2157, y el módulo Virtual Desktop en Symantec On-Demand Protection (SODP) anterior 2.6 Build 2233, no encripta de forma adecuada archivos que estén sujetos a la política de encriptación automática, lo cual permitiría a un usuario local leer datos sensible a… | |
| Modificada | Media (5) | 2.4% | — | ISS Blackice PC ProtectionISS Blackice Server ProtectionISS Proventia DesktopISS Realsecure Desktop+6 | 27/7/2006 | 16/6/2026 | La funcionalidad SMB Mailslot en PAM en múltiples productos ISS con XPU (24.39/1.78/epj/x.x.x.1780), incluyendo Proventia A, G, M, Server, y Desktop, BlackICE PC y Server Protection 3.6, y RealSecure 7.0,permiten a atacantes remotos provocar denegación de servicio (bucle infinito) a través de paquetes SMB manipulados… | |
| Modificada | Alta (7.5) | 6.2% | — | HP Openview Storage Data Protector | 24/5/2006 | 16/6/2026 | Unspecified vulnerability in HP OpenView Storage Data Protector 5.1 and 5.5 allows remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Fileprotection Express | 4/5/2006 | 16/6/2026 | FileProtection Express 1.0.1 and earlier allows remote attackers to bypass authentication via a cookie with an Admin value of 1. | |
| Modificada | Baja (3.5) | 0.96% | — | Inprotect | 19/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in zones.php in Inprotect 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) Name or (2) Description field. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5.1) | 1.9% | — | Trend Micro Interscan Messaging Security SuiteTrend Micro Interscan WEB Security SuiteTrend Micro Serverprotect | 10/2/2006 | 16/6/2026 | Trend Micro ServerProtect 5.58, and possibly InterScan Messaging Security Suite and InterScan Web Security Suite, have a default configuration setting of "Do not scan compressed files when Extracted file count exceeds 500 files," which may be too low in certain circumstances, which allows remote attackers to bypass… | |
| Modificada | Media (5) | 12% | 💥 Exploit | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business… | |
| Modificada | Media (5) | 3.8% | — | Broadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor Mobile BackupBroadcom Business Protection SuiteBroadcom Desktop Protection Suite+3 | 19/1/2006 | 16/6/2026 | The DM Primer in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection… | |
| Modificada | Alta (7.2) | 0.37% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop | 31/12/2005 | 16/6/2026 | ISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and 7.0, does not drop privileges before launching help from the "More Info" button in the "Application Protection" dialog, which allows local users to execute arbitrary… | |
| Modificada | Media (4.6) | 0.44% | — | Sygate Technologies Protection Agent | 28/12/2005 | 16/6/2026 | SmcGui.exe in Sygate Protection Agent 5.0 build 6144 allows local users to obtain management control over the agent by executing the GUI (SmcGui.exe) and then killing the process, which causes the privileged management GUI to launch. | |
| Modificada | Alta (7.8) | 3.7% | — | Trend Micro Serverprotect Earthagent | 14/12/2005 | 16/6/2026 | Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU consumption) via a flood of crafted packets with a certain "magic… | |
| Modificada | Alta (7.5) | 4.9% | — | Trend Micro Serverprotect | 14/12/2005 | 16/6/2026 | Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbitrary code via "wrapped" length values in Chunked transfer… | |
| Modificada | Media (5) | 1.9% | — | Trend Micro Serverprotect | 14/12/2005 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en componente Crystal Report (rptserver.asp) en Tren Micro Server Protect Managemente Console 5.58, usada en Control Manager 2.5 y 3.0 y Damage Cleanup Server 1.1, y posiblemente versiones anteriores, permite a atacantes remotos leer ficheros de su elección mediante el… | |
| Modificada | Media (5.1) | 1.7% | — | Proland Protector Plus | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Proland Protector Plus 2000 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even… | |
| Modificada | Baja (2.1) | 0.25% | — | Advansysperu Software USB Lock Auto-protect | 14/9/2005 | 16/6/2026 | Advansysperu Software USB Lock Auto-Protect (AP) 1.5 uses a weak encryption scheme to encrypt passwords, which allows local users to gain sensitive information and bypass USB interface protection. | |
| Modificada | Media (4.3) | 1.3% | — | Php.warpedweb.net Phppageprotect | 20/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en PHPPageProtect 1.0.0a permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "username" en "admin.php" o "login.php". | |
| Modificada | Media (5) | 1.4% | — | Sven-ove Bjerkan Downloadprotect | 13/7/2005 | 16/6/2026 | Vulnerabilidad de franqueo de directorioes en DownloadProtect anterior a la 1.0.3 permite que atacantes remotos lean ficheros por encima de la carpeta de descarga. | |
| Modificada | Alta (7.5) | 4.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+11 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with long header file names that modify pointers within a structure. | |
| Modificada | Baja (2.6) | 1.0% | — | Nprotect Netizen | 13/4/2005 | 16/6/2026 | nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files. | |
| Modificada | Media (4.6) | 0.34% | — | Inca Nprotect Gameguard | 17/1/2005 | 16/6/2026 | npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges. | |
| Modificada | Media (4.6) | 0.42% | — | ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop | 31/12/2004 | 16/6/2026 | Buffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users to gain system privileges by modifying the .INI file to contain a long packetLog.fileprefix value. |