Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Call-cc Chicken | 31/10/2019 | 16/6/2026 | Buffer overflow in the thread scheduler in Chicken before 4.8.0.1 allows attackers to cause a denial of service (crash) by opening a file descriptor with a large integer value. | |
| Modificada | Alta (8.8) | 4.6% | — | Call-cc ChickenDebian Linux | 31/10/2019 | 16/6/2026 | OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. | |
| Modificada | Media (6.5) | 1.0% | — | Jenkins Call Remote JOB | 25/9/2019 | 17/6/2026 | Jenkins Call Remote Job Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Alta (8.8) | 0.91% | — | Ranksol Live Call Support | 19/6/2019 | 17/6/2026 | CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco IP Conference Phone 7832 FirmwareCisco IP Conference Phone 8832 FirmwareCisco IP Phone 7811 FirmwareCisco IP Phone 7821 Firmware+12 | 3/5/2019 | 17/6/2026 | A vulnerability in the call-handling functionality of Session Initiation Protocol (SIP) Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause an affected phone to reload unexpectedly, resulting in a temporary denial of service (DoS) condition. The… | |
| Modificada | Crítica (9.8) | 3.6% | — | Activision Call OF Duty\ | 19/4/2019 | 17/6/2026 | SV_SteamAuthClient in various Activision Infinity Ward Call of Duty games before 2015-08-11 is missing a size check when reading authBlob data into a buffer, which allows one to execute code on the remote target machine when sending a steam authentication request. This affects Call of Duty: Modern Warfare 2, Call of… | |
| Modificada | Crítica (9.8) | 1.6% | — | Overit Geocall | 1/4/2019 | 17/6/2026 | An issue was discovered in OverIT Geocall 6.3 before build 2:346977. An unauthenticated servlet allows an attacker to obtain a cookie of an authenticated user, and login to the web application. | |
| Modificada | Alta (8.8) | 1.8% | — | Overit Geocall | 1/4/2019 | 17/6/2026 | An issue was discovered in OverIT Geocall 6.3 before build 2:346977. Weak authentication and session management allows an authenticated user to obtain access to the Administrative control panel and execute administrative functions. | |
| Modificada | Alta (7.5) | 2.2% | — | Overit Geocall | 1/4/2019 | 17/6/2026 | An log-management directory traversal issue was discovered in OverIT Geocall 6.3 before build 2:346977. | |
| Modificada | Media (6.1) | 0.90% | — | Overit Geocall | 1/4/2019 | 17/6/2026 | Multiple XSS vulnerabilities were discovered in OverIT Geocall 6.3 before build 2:346977. | |
| Modificada | Media (4.4) | 0.34% | — | Avaya Call Management System Supervisor | 24/9/2018 | 17/6/2026 | A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x. | |
| Modificada | Media (5.3) | 1.2% | — | Call Project Call | 31/5/2018 | 17/6/2026 | call is an HTTP router that is primarily used by the hapi framework. There exists a bug in call versions 2.0.1-3.0.1 that does not validate empty parameters, which could result in invalid input bypassing the route validation rules. | |
| Modificada | Crítica (10) | 30% | 💥 Exploit | Activision Call OF Duty Modern Warfare 2 | 3/5/2018 | 17/6/2026 | Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets. | |
| Modificada | Alta (8.8) | 15% | 💥 Exploit | HP Opencall Media Platform | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x). | |
| Modificada | Media (6.1) | 8.0% | 💥 Exploit | HP Opencall Media Platform | 15/2/2018 | 17/6/2026 | A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x). | |
| Modificada | Media (6.1) | 2.6% | 💥 Exploit | Inboundnow Call TO Action | 11/9/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to… | |
| Modificada | Alta (7.5) | 0.94% | — | Call-cc Chicken | 17/7/2017 | 17/6/2026 | Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, will result in O(n) lookup time. | |
| Modificada | Alta (7.5) | 3.1% | — | Call-cc Spiffy | 7/6/2017 | 17/6/2026 | Directory traversal vulnerability in Spiffy before 5.4. | |
| Modificada | Alta (7.5) | 1.5% | — | Call-cc Chicken | 1/6/2017 | 17/6/2026 | An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it. | |
| Modificada | Media (5.9) | 0.67% | — | K-opticom Corporation Business Lala Call | 28/4/2017 | 17/6/2026 | The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.67% | — | K-opticom Corporation Lala Call | 28/4/2017 | 17/6/2026 | The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.1% | — | Call-cc Chicken | 29/3/2017 | 17/6/2026 | The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash). | |
| Modificada | Media (5.4) | 0.54% | — | IBM Call Center FOR Commerce | 27/3/2017 | 17/6/2026 | IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 2000442. | |
| Modificada | Alta (8.1) | 1.5% | — | Call-cc Chicken | 16/3/2017 | 17/6/2026 | An issue was discovered in CHICKEN Scheme through 4.12.0. When using a nonstandard CHICKEN-specific extension to allocate an SRFI-4 vector in unmanaged memory, the vector size would be used in unsanitised form as an argument to malloc(). With an unexpected size, the impact may have been a segfault or buffer overflow. | |
| Modificada | Alta (7.5) | 1.8% | — | Call-cc Chicken | 10/1/2017 | 17/6/2026 | The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12… |