Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1895 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | Cisco Voip Phone Cp-7940Cisco Skinny Client Control Protocol Software | 4/10/2002 | 16/6/2026 | Cisco IP Phone (VoIP) models 7910, 7940, and 7960 allow remote attackers to cause a denial of service (crash) via malformed packets as demonstrated by (1) "jolt", (2) "jolt2", (3) "raped", (4) "hping2", (5) "bloop", (6) "bubonic", (7) "mutant", (8) "trash", and (9) "trash2." | |
| Modificada | Media (5) | 1.3% | — | Cisco VPN Client | 5/9/2002 | 16/6/2026 | Desbordamiento de búfer en Cliente de Red Privada Virtual (VPN) de Cisco 3.5.4 y anteriores permite a atacantes remotos causar una denegación de servicio mediante un Intecambio de Clave de Intenet (Internet Key Exchange - IKE) con un contenido útil (payload) de una Índice de Parámetro de Seguridad (Security Parameter… | |
| Modificada | Media (5) | 2.2% | — | Cisco VPN Client | 5/9/2002 | 16/6/2026 | El Cliente de Red Privada Virtual (VPN) de Cisco 3.5.4 y anteriores permite a atacantes remotos causar una denegación de servicio (consumición de CPU) mediante un paquete con una carga útil de longitud cero. | |
| Modificada | Alta (7.2) | 1.5% | 💥 Exploit | Cisco VPN Client | 28/5/2002 | 16/6/2026 | Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative privileges via a long profile name in a connect argument. | |
| Modificada | Media (5) | 5.4% | — | FreeradiusGNU RadiusIcradiusLivingston Radius+7 | 4/3/2002 | 16/6/2026 | Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2. | |
| Modificada | Alta (7.5) | 8.5% | — | Ascend RadiusFreeradiusGNU RadiusIcradius+8 | 4/3/2002 | 16/6/2026 | Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data. | |
| Modificada | Alta (7.5) | 2.2% | — | Citrix ICA Client | 13/12/2001 | 16/6/2026 | El cliente Citrix Independent Computing Architecture (ICA) para Windows 6.1 permite a sitios web remotos con intenciones maliciosas, la ejecución de código arbitrario mediante un fichero .ICA, que es descargado y automáticamente ejecutado por el cliente. | |
| Modificada | Media (5) | 1.2% | — | Gnutella Client | 31/8/2001 | 16/6/2026 | Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags. | |
| Modificada | Alta (10) | 3.1% | — | Lotus Domino R5 ClientLotus Domino R5 Server | 12/3/2001 | 16/6/2026 | Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier. | |
| Modificada | Alta (10) | 2.0% | — | Novell ClientSymantec Norton Antivirus | 20/10/2000 | 16/6/2026 | Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Alt-n Worldclient | 12/7/2000 | 16/6/2026 | The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Alta (10) | 6.7% | — | ISC Dhcp Client | 24/6/2000 | 16/6/2026 | ISC DHCP client program dhclient allows remote attackers to execute arbitrary commands via shell metacharacters. | |
| Modificada | Baja (2.1) | 0.77% | — | Napster Client | 26/3/2000 | 16/6/2026 | Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message. | |
| Modificada | Alta (7.5) | 3.2% | — | ISC Dhcp Client | 31/12/1999 | 16/6/2026 | Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options. | |
| Modificada | Media (4.6) | 0.33% | — | Prosoft Engineering Netware Client | 14/11/1999 | 16/6/2026 | ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session. | |
| Modificada | Alta (7.5) | 2.7% | — | Mutt Mail Client | 27/9/1999 | 16/6/2026 | Buffer overflow in mutt mail client allows remote attackers to execute commands via malformed MIME messages. | |
| Modificada | Media (5) | 1.6% | — | Kvirc IRC Client | 24/9/1999 | 16/6/2026 | Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request. | |
| Modificada | Media (4.6) | 0.35% | — | Gftp FTP Client | 5/9/1999 | 16/6/2026 | El cliente de FTP gFTP versión 1.13, y otras versiones anteriores a 2.0.0 almacenan contraseñas en texto plano en (1) la ventana de registro(log) o (2) en un fichero de registro. | |
| Modificada | Media (4.6) | 0.32% | — | Backweb Technologies Backweb Client | 24/12/1998 | 16/6/2026 | BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password. | |
| Modificada | Media (5.1) | 1.2% | — | Palace Client | 2/10/1998 | 16/6/2026 | A malicious Palace server can force a client to execute arbitrary programs. |