Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1838 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.33%—Paul Jarc Idtools26/6/200116/6/2026
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.
ModificadaAlta (7.2)0.42%—Redhat Linux PowertoolsZopeConectiva LinuxDebian Linux+312/3/200116/6/2026
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
ModificadaBaja (2.1)0.52%—HP Support Tools Manager12/2/200116/6/2026
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.
ModificadaMedia (5)4.7%💥 ExploitNetwork Associates NET Tools PKI Server20/10/200016/6/2026
Buffer overflow in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary commands via a long URL in the HTTPS port.
ModificadaMedia (5)2.9%💥 ExploitNetwork Associates NET Tools PKI Server20/10/200016/6/2026
Directory traversal vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTPS request to the enrollment server.
ModificadaAlta (7.5)5.2%💥 ExploitNetwork Associates NET Tools PKI Server20/10/200016/6/2026
Format string vulnerability in strong.exe program in NAI Net Tools PKI server 1.0 before HotFix 3 allows remote attackers to execute arbitrary code via format strings in a URL with a .XUDA extension.
ModificadaAlta (7.6)4.9%—Adobe AcrobatAdobe Acrobat Business ToolsAdobe Acrobat Reader20/10/200016/6/2026
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.
ModificadaAlta (7.2)0.36%—SGI Workshop Debugger AND Performance Tools20/6/200016/6/2026
Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.
ModificadaMedia (5)1.7%—Network Associates NET Tools PKI Server19/6/200016/6/2026
Net Tools PKI Server allows remote attackers to cause a denial of service via a long HTTP request.
ModificadaMedia (5)1.6%—Network Associates NET Tools PKI Server19/6/200016/6/2026
Net Tools PKI Server does not properly restrict access to remote attackers when the XUDA template files do not contain absolute pathnames for other files.
ModificadaAlta (7.5)3.0%—Redhat Linux PowertoolsZope15/6/200016/6/2026
The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.
ModificadaAlta (10)9.9%💥 ExploitDnstools Software Dnstools2/3/200016/6/2026
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.
ModificadaMedia (5)2.6%—Dnstools Software Dnstools31/12/199916/6/2026
DNS allows remote attackers to use DNS name servers as traffic amplifiers via a UDP DNS query with a spoofed source address, which produces more traffic to the victim than was sent by the attacker.