Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2861▲ 225 respecto a la semana anterior
Críticas / altas1331▼ 100 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1895 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)3.0%—Safenet Softremote VPN Client31/12/200216/6/2026
SafeNet VPN client allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key Exchange (IKE) response packets, possibly involving buffer overflows using (1) a large Security Parameter Index (SPI) field, (2) a large number of payloads, or (3) a long payload.
ModificadaBaja (2.1)0.38%—Novell Netware Client31/12/200216/6/2026
Buffer overflow in Novell NetWare Client 4.80 through 4.83 allows local users to cause a denial of service (crash) by using ping, traceroute, or a similar utility to force the client to resolve a large hostname.
ModificadaAlta (7.5)4.2%💥 ExploitBrowseftp Client31/12/200216/6/2026
Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" message reply.
ModificadaAlta (10)80%💥 ExploitCisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+323/12/200216/6/2026
Multiple SSH2 servers and clients do not properly handle large packets or large fields, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code via buffer overflow attacks, as demonstrated by the SSHredder SSH protocol test suite.
ModificadaAlta (10)6.1%—Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+323/12/200216/6/2026
Multiple SSH2 servers and clients do not properly handle strings with null characters in them when the string length is specified by a length field, which could allow remote attackers to cause a denial of service or possibly execute arbitrary code due to interactions with the use of null-terminated strings as…
ModificadaAlta (10)5.8%—Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+323/12/200216/6/2026
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
ModificadaAlta (10)9.8%—Cisco IOSFissh SSH ClientIntersoft SecurenettermNetcomposite Shellguard SSH+323/12/200216/6/2026
Multiple SSH2 servers and clients do not properly handle packets or data elements with incorrect length specifiers, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.
ModificadaMedia (5)1.6%—Cisco VPN Client4/10/200216/6/2026
Cisco Virtual Private Network (VPN) Client software 2.x.x and 3.x before 3.0.5 allows remote attackers to cause a denial of service (crash) via TCP packets with source and destination ports of 137 (NETBIOS).
ModificadaMedia (5)1.4%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via (1) malformed or (2) large ISAKMP packets.
ModificadaMedia (5)3.4%💥 ExploitCisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.
ModificadaMedia (5)1.2%—Cisco VPN Client4/10/200216/6/2026
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.6(Rel), when configured with all tunnel mode, can be forced into acknowledging a TCP packet from outside the tunnel.
ModificadaMedia (6.4)2.7%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
The web server for Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allows remote attackers to cause a denial of service (reset) and possibly read sensitive memory via a large integer value in (1) the stream ID of the StreamingStatistics script, or (2) the port ID of the PortInformation script.
ModificadaMedia (4.6)0.38%—Cisco VPN Client4/10/200216/6/2026
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, allows local users to use a utility program to obtain the group password.
ModificadaAlta (7.5)1.8%—Cisco VPN Client4/10/200216/6/2026
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.2B, does not generate sufficiently random numbers, which may make it vulnerable to certain attacks such as spoofing.
ModificadaMedia (5)1.6%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Information leaks in Cisco VPN 3000 Concentrator 2.x.x and 3.x.x before 3.5.4 allow remote attackers to obtain potentially sensitive information via the (1) SSH banner, (2) FTP banner, or (3) an incorrect HTTP request.
ModificadaMedia (5)1.0%—Cisco VPN 3000 Concentrator Series SoftwareCisco Secure Access Control ServerCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set.
ModificadaMedia (5)1.7%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to cause a denial of service (crash) via a long (1) username or (2) password to the HTML login interface.
ModificadaAlta (7.5)0.95%—Cisco VPN Client4/10/200216/6/2026
Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks.
ModificadaAlta (7.5)1.1%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.2, allows restricted administrators to obtain certificate passwords that are stored in plaintext in the HTML source code for Certificate Management pages.
ModificadaAlta (7.5)1.3%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the concentrator.
ModificadaMedia (5)1.6%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
The LAN-to-LAN IPSEC capability for Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.4, allows remote attackers to cause a denial of service via an incoming LAN-to-LAN connection with an existing security association with another device on the remote network, which causes the concentrator to remove the previous…
ModificadaAlta (7.5)3.9%—Edonkey2000 Edonkey 2000 Client4/10/200216/6/2026
Buffer overflow in eDonkey 2000 35.16.60 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long "ed2k:" URL.
ModificadaBaja (2.1)0.39%—Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software4/10/200216/6/2026
Cisco IP Phone (VoIP) models 7910, 7940, and 7960 use a default administrative password, which allows attackers with physical access to the phone to modify the configuration settings.
ModificadaAlta (7.5)1.3%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code.
ModificadaMedia (5)1.5%—Cisco VPN 3000 Concentrator Series SoftwareCisco VPN 3002 Hardware Client4/10/200216/6/2026
Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, allows remote attackers to obtain potentially sensitive information without authentication by directly accessing certain HTML pages.