Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
251 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 18% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that… | |
| Modificada | Media (5) | 18% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and… | |
| Modificada | Media (5) | 3.0% | — | Sophos Anti-virus | 1/11/2006 | 16/6/2026 | Sophos Anti-Virus 5.1 allows remote attackers to cause a denial of service (memory consumption) via a file that is compressed with Petite and contains a large number of sections. | |
| Modificada | Media (6.4) | 21% | 💥 Exploit | Sophos Anti-virusSophos Endpoint Security | 1/11/2006 | 16/6/2026 | Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name… | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus PersonalKaspersky LAB Kaspersky Anti-virus Personal PROKaspersky LAB Kaspersky Internet Security | 20/10/2006 | 16/6/2026 | The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code via crafted Irp structure with invalid addresses in the… | |
| Modificada | Alta (7.5) | 21% | 💥 Exploit | Clam Anti-virus Clamav | 16/10/2006 | 16/6/2026 | Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Clam Anti-virus Clamav | 16/10/2006 | 16/6/2026 | Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location." | |
| Modificada | Media (5) | 1.6% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Service Platform FOR Service Providers | 10/7/2006 | 16/6/2026 | F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and Service Platform for Service Providers 6.x and earlier does not scan files contained on removable media when "Scan network drives" is disabled, which allows remote attackers to bypass anti-virus controls. | |
| Modificada | Media (5) | 1.6% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Service Platform FOR Service Providers | 10/7/2006 | 16/6/2026 | F-Secure Anti-Virus 2003 through 2006 and other versions, Internet Security 2003 through 2006, and Service Platform for Service Providers 6.x and earlier allows remote attackers to bypass anti-virus scanning via a crafted filename. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Kaspersky Anti-virusKaspersky Internet Security | 19/6/2006 | 16/6/2026 | klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject,… | |
| Modificada | Alta (7.6) | 5.7% | — | F-secure Anti-virusF-secure Internet Gatekeeper | 6/6/2006 | 16/6/2026 | Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from… | |
| Modificada | Alta (7.2) | 0.48% | — | Clam Anti-virus ClamavClam Anti-virus Clamxav | 17/5/2006 | 16/6/2026 | freshclam in (1) Clam Antivirus (ClamAV) 0.88 and (2) ClamXav 1.0.3h and earlier does not drop privileges before processing the config-file command line option, which allows local users to read portions of arbitrary files when an error message displays the first line of the target file. | |
| Modificada | Alta (7.5) | 22% | — | Sophos Anti-virus | 10/5/2006 | 16/6/2026 | Multiple Sophos Anti-Virus products, including Anti-Virus for Windows 5.x before 5.2.1 and 4.x before 4.05, when cabinet file inspection is enabled, allows remote attackers to execute arbitrary code via a CAB file with "invalid folder count values," which leads to heap corruption. | |
| Modificada | Media (5.1) | 5.8% | — | Clam Anti-virus Clamav | 1/5/2006 | 16/6/2026 | Buffer overflow in the get_database function in the HTTP client in Freshclam in ClamAV 0.80 to 0.88.1 might allow remote web servers to execute arbitrary code via long HTTP headers. | |
| Modificada | Media (5.1) | 7.8% | — | Clam Anti-virus Clamav | 6/4/2006 | 16/6/2026 | Integer overflow in the cli_scanpe function in the PE header parser (libclamav/pe.c) in Clam AntiVirus (ClamAV) before 0.88.1, when ArchiveMaxFileSize is disabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 5.3% | — | Clam Anti-virus Clamav | 6/4/2006 | 16/6/2026 | The cli_bitset_set function in libclamav/others.c in Clam AntiVirus (ClamAV) before 0.88.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger an "invalid memory access." | |
| Modificada | Alta (7.8) | 2.9% | — | Kaspersky LAB Kaspersky Anti-virus | 9/3/2006 | 16/6/2026 | Kaspersky Antivirus 5.0.5 and 5.5.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via unknown attack vectors. | |
| Modificada | Alta (7.5) | 5.8% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Internet GatekeeperSolutions Based ON F-secure Personal Express | 21/1/2006 | 16/6/2026 | Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives. | |
| Modificada | Media (5) | 3.0% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper | 21/1/2006 | 16/6/2026 | Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP… | |
| Modificada | Alta (7.5) | 10% | — | Clam Anti-virus Clamav | 10/1/2006 | 16/6/2026 | Heap-based buffer overflow in libclamav/upx.c in Clam Antivirus (ClamAV) before 0.88 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted UPX files. | |
| Modificada | Media (5) | 8.5% | — | Sophos Anti-virus | 31/12/2005 | 16/6/2026 | Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned. | |
| Modificada | Alta (7.5) | 4.3% | — | F-secure Anti-virusKaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus Personal | 18/11/2005 | 16/6/2026 | Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file. | |
| Modificada | Alta (7.2) | 0.35% | — | Kaspersky LAB Kaspersky Anti-virus | 18/11/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder. | |
| Modificada | Alta (10) | 2.2% | — | Clam Anti-virus Clamav | 16/11/2005 | 16/6/2026 | Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors. | |
| Modificada | Alta (7.2) | 0.80% | 💥 Exploit | F-secure Anti-virusF-secure Internet Gatekeeper | 16/11/2005 | 16/6/2026 | suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege. |