Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
225 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.85% | 💥 Exploit | Trendmicro Officescan | 27/4/2009 | 16/6/2026 | NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.6) | 0.40% | — | Trend Micro Internet Security 2007Trend Micro Internet Security 2008Trend Micro Officescan | 21/1/2009 | 16/6/2026 | The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to… | |
| Modificada | Alta (10) | 6.4% | — | Trend Micro Internet Security 2007Trend Micro Internet Security 2008Trend Micro Officescan | 21/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet… | |
| Modificada | Media (5) | 2.1% | — | Trend Micro Internet Security 2007Trend Micro Internet Security 2008Trend Micro Officescan | 21/1/2009 | 16/6/2026 | The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value… | |
| Modificada | Alta (10) | 18% | — | Trend Micro Officescan | 23/10/2008 | 16/6/2026 | Stack-based buffer overflow in CGI programs in the server in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1374, and 8.0 SP1 Patch 1 before build 3110, allows remote attackers to execute arbitrary code via an HTTP POST request containing crafted form data, related to "parsing CGI requests." | |
| Modificada | Media (5) | 3.2% | — | Trend Micro Officescan | 3/10/2008 | 16/6/2026 | The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via crafted HTTP headers, related to the "error handling mechanism." | |
| Modificada | Alta (10) | 5.5% | — | Trend Micro Officescan | 3/10/2008 | 16/6/2026 | Multiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5) | 20% | — | Trend Micro OfficescanTrend Micro Worry Free Business Security | 3/10/2008 | 16/6/2026 | Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business… | |
| Modificada | Alta (10) | 6.7% | — | Trend Micro Client-server-messaging SecurityTrend Micro Officescan | 16/9/2008 | 16/6/2026 | Stack-based buffer overflow in cgiRecvFile.exe in Trend Micro OfficeScan 7.3 patch 4 build 1362 and other builds, OfficeScan 8.0 and 8.0 SP1, and Client Server Messaging Security 3.6 allows remote attackers to execute arbitrary code via an HTTP request containing a long ComputerName parameter. | |
| Modificada | Crítica (9.8) | 11% | — | Trendmicro Client Server Messaging SuiteTrendmicro OfficescanTrendmicro Worry-free Business Security | 27/8/2008 | 16/6/2026 | The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be… | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Trend Micro Officescan | 30/7/2008 | 16/6/2026 | Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and Worry-Free Business Security (WFBS) 5.0 allows… | |
| Modificada | Alta (9.3) | 4.1% | 💥 Exploit | Panda Activescan | 11/7/2008 | 16/6/2026 | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method. | |
| Modificada | Alta (9.3) | 7.7% | 💥 Exploit | Panda Activescan | 11/7/2008 | 16/6/2026 | Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method. | |
| Modificada | Media (6.4) | 51% | 💥 Exploit | Trend Micro Officescan Corporate Edition | 17/3/2008 | 16/6/2026 | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1)… | |
| Modificada | Media (5) | 2.2% | — | Trend Micro Officescan Corporate Edition | 17/3/2008 | 16/6/2026 | Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Microworld Technologies EscanMicroworld Technologies Escan Management ConsoleMicroworld Technologies Escan Server | 10/3/2008 | 16/6/2026 | Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command. | |
| Modificada | Alta (7.2) | 0.89% | 💥 Exploit | Microworld Technologies Escan Anti-virusMicroworld Technologies Escan Internet SecurityMicroworld Technologies Escan Virus Control | 31/8/2007 | 16/6/2026 | MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe. | |
| Modificada | Alta (10) | 5.5% | — | Trend Micro Officescan | 27/6/2007 | 16/6/2026 | Stack-based buffer overflow in CGIOCommon.dll before 8.0.0.1042 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to execute arbitrary code via long crafted requests, as demonstrated using a long session cookie to unspecified CGI programs that use this library. | |
| Modificada | Alta (10) | 3.0% | — | Trend Micro Officescan | 27/6/2007 | 16/6/2026 | cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and gain access to the Management Console via an empty hash and empty encrypted password string, related to "stored decrypted user logon information." | |
| Modificada | Alta (10) | 5.5% | — | Microworld Technologies Escan | 24/5/2007 | 16/6/2026 | Stack-based buffer overflow in the MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan before 9.0.718.1 allows remote attackers to execute arbitrary code via a long command. | |
| Modificada | Alta (7.8) | 3.0% | — | Panda ActivescanPanda AntivirusPanda Platinum 2006 Internet SecurityPanda Platinum 2007 Internet Security+2 | 9/5/2007 | 16/6/2026 | Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file. | |
| Modificada | Alta (10) | 2.8% | — | Microworld Technologies Escan | 2/5/2007 | 16/6/2026 | The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute arbitrary commands by connecting directly to TCP port 2222. | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | Trend Micro Client-server-messaging SecurityTrend Micro Officescan Corporate Edition | 20/2/2007 | 16/6/2026 | Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupINI.dll, as used in OfficeScan 7.0 before Build 1344, OfficeScan 7.3 before Build 1241, and Client / Server / Messaging Security 3.0 before Build 1197, allow remote attackers to execute arbitrary code… | |
| Modificada | Alta (9.3) | 8.4% | — | Trend Micro Client-server-messaging Suite SMBTrend Micro Client-server Suite SMBTrend Micro Control ManagerTrend Micro Interscan Emanager+19 | 8/2/2007 | 16/6/2026 | Buffer overflow in the Trend Micro Scan Engine 8.000 and 8.300 before virus pattern file 4.245.00, as used in other products such as Cyber Clean Center (CCC) Cleaner, allows remote attackers to execute arbitrary code via a malformed UPX compressed executable. | |
| Modificada | Alta (7.8) | 2.7% | — | Trend Micro OfficescanTrend Micro PC Cillin - Internet Security 2006Trend Micro Serverprotect | 11/12/2006 | 16/6/2026 | The Trend Micro scan engine before 8.320 for Windows and before 8.150 on HP-UX and AIX, as used in Trend Micro PC Cillin - Internet Security 2006, Office Scan 7.3, and Server Protect 5.58, allows remote attackers to cause a denial of service (CPU consumption and system hang) via a malformed RAR archive with an Archive… |