Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1909 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)5.0%—Netegrity Sideminder Affiliate Agent18/8/200416/6/2026
Desbordamiento de búfer basado en el montón en SiteMinder Affilitate Agent 4.x permite a atacantes remotos ejecutar código de su elección mediante una cookie SMPROFILE grande.
ModificadaAlta (7.5)3.8%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Stack-based buffer overflow in the client for Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and Citrix MetaFrame Presentation Server client for WinCE before 8.33 allows remote attackers to execute arbitrary code via a long cached icon filename in the InName XML element.
ModificadaMedia (5)1.2%—Citrix Metaframe ClientCitrix Program Neighborhood Agent26/4/200416/6/2026
Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive.
ModificadaAlta (7.5)73%💥 ExploitISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/4/200416/6/2026
Múltiples desbordamientos de búfer basado en la pila en las rutinas de análisis de ICQ en el componente ISS Protocol Analysis Module (PAM), utilizado en varios productos RealSecure, Proventia y BlackICE, permite a atacantes remotos ejecutar código arbitrario mediante un respuesta SRV_MULTI conteniendo un paquete de…
ModificadaAlta (7.5)8.0%—ISS Blackice Agent ServerISS Blackice PC ProtectionISS Blackice Server ProtectionISS Realsecure Desktop+715/3/200416/6/2026
Desbordamiento de búfer basado en la pila en el Módulo de análisis de Protocolos (PAM) de ISS, usado en ciertas versiones de RealSecure Network 7.0 y Server Sensor 7.0, Proventia series A, G, y M, Desktop 7.0 y 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, y BlackICE Server Protection…
ModificadaAlta (10)3.8%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
ModificadaMedia (5)2.4%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
ModificadaAlta (10)5.2%—HP Insight Management SuiteHP Insight ManagerHP Remote Diagnostics Enabling Agent31/12/200316/6/2026
Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges or cause a denial of service via unknown attack vectors.
ModificadaMedia (4.3)1.2%—RSA ACE Agent24/7/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en la función de redirección segura de RSA ACE/Agent 5.0 para Windows, y 5.x para Web, permite a atacantes remotos insertar script web arbitrario y posiblemente causar que usuarios entren una contraseña mediante una petición GET que contenga el scritp.
ModificadaAlta (7.5)2.1%—HP Openview Emanate Snmp AgentHP Vvos11/4/200316/6/2026
Vulnerabilidad o vulnerabilidades desconocidas en módulos SNMP de HP OpenView EMANATE 14.2 SNMP permite que el nombre de comunidad de lectura y escritura quede expuesto, vulnerabilidad relacionada con "acceso de comunidad de sólo lectura" y/o "nombre de comunidad fácil de adivinar".
ModificadaMedia (4.3)3.0%💥 ExploitCompaq Insight Management Agent31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remote attackers to inject arbitrary web script or HTML via a URL, which inserts the script into the resulting error message.
ModificadaMedia (4.6)0.39%—Mcafee Entercept Agent31/12/200216/6/2026
Entercept Agent 2.5 agent for Windows, released before May 21, 2002, allows local administrative users to obtain the entercept agent password, which could allow the administrators to log on as the entercept_agent account and conceal their identity.
ModificadaAlta (7.5)1.5%—ISS Blackice Agent4/10/200216/6/2026
BlackICE Agent 3.1.eal does not always reactivate after a system standby, which could allow remote attackers and local users to bypass intended firewall restrictions.
ModificadaMedia (5)1.3%—ISS Blackice Agent4/10/200216/6/2026
The default configuration of BlackICE Agent 3.1.eal and 3.1.ebh has a high tcp.maxconnections setting, which could allow remote attackers to cause a denial of service (memory consumption) via a large number of connections to the BlackICE system that consumes more resources than intended by the user.
ModificadaAlta (7.5)3.7%—ISS Blackice AgentISS Blackice DefenderISS Realsecure Server Sensor29/5/200216/6/2026
Desbordamiento de búfer en ISS BlackICE Defender 2.9 y anteriores, BlackICE Agente 3.0 y 3.1, y RealSecure Server Sensor 6.01 y 6.5 permiten a atacantes remotos que provoquen una denegación de servicio (caida) y posiblemente ejecutar código arbitrario por medio de un envío masivo de grandes paquetes ping ICMP.
ModificadaMedia (4.6)0.40%—Compaq Management Agents30/10/200116/6/2026
Buffer overflow in Compaq Management Agents before 5.2, included in Compaq Web-enabled Management Software, allows local users to gain privileges.
ModificadaAlta (10)4.0%—Compaq Armada Insight ManagerCompaq Enterprise Volume Manager-command ScripterCompaq Foundation AgentsCompaq Insight Management Agent+1112/3/200116/6/2026
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.
ModificadaAlta (7.5)1.3%—Network Associates Sniffer Agent9/1/200116/6/2026
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.
ModificadaMedia (5)1.3%—Network Associates Sniffer Agent9/1/200116/6/2026
NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.
ModificadaAlta (7.5)1.5%—Network Associates Sniffer Agent9/1/200116/6/2026
NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.
ModificadaAlta (10)3.5%—Network Associates Sniffer Agent9/1/200116/6/2026
Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.
ModificadaAlta (7.5)2.4%💥 ExploitBroadcom Inoculateit Agent FOR Exchange31/12/200023/9/2026
Computer Associates InoculateIT Agent para Exchange Servidor no reconoce un archivo adjunto de virus de correo electrónico si la cabecera SMTP carece del campo 'From', lo que permite a atacantes remotos eludir la protección antivirus.
ModificadaAlta (7.5)1.3%—ISS Blackice AgentISS Blackice Defender22/6/200016/6/2026
BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.
ModificadaAlta (7.5)1.5%—Compaq Insight Management AgentCompaq Management Agents FOR Servers31/12/199916/6/2026
BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.
ModificadaAlta (7.2)0.92%💥 ExploitBMC Patrol Agent13/7/199916/6/2026
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.