Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 4.1% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path"). | |
| Modificada | Alta (10) | 10% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the… | |
| Modificada | Media (5) | 8.8% | 💥 Exploit | Symantec Client FirewallSymantec Client SecuritySymantec Norton Internet SecuritySymantec Norton Personal Firewall | 18/8/2004 | 16/6/2026 | SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 and 1.1 allow remote attackers to cause a denial of service (infinite loop) via a TCP packet with (1) SACK option or (2) Alternate Checksum Data option… | |
| Modificada | Baja (2.6) | 11% | 💥 Exploit | Symantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+1 | 7/7/2004 | 16/6/2026 | The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allows remote attackers to cause a denial of service (CPU consumption from infinite loop)… | |
| Modificada | Alta (10) | 13% | — | Symantec Client FirewallSymantec Client SecuritySymantec Norton AntispamSymantec Norton Internet Security+1 | 7/7/2004 | 16/6/2026 | Multiple vulnerabilities in SYMDNS.SYS for Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall 2002 through 2004, Norton AntiSpam 2004, Client Firewall 5.01 and 5.1.1, and Client Security 1.0 through 2.0 allow remote attackers to cause a denial of service or execute arbitrary… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Personal Assistant | 3/2/2004 | 16/6/2026 | Cisco Personal Assistant 1.4(1) and 1.4(2) disables password authentication when "Allow Only Cisco CallManager Users" is enabled and the Corporate Directory settings refer to the directory service being used by Cisco CallManager, which allows remote attackers to gain access with a valid username. | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Alta (7.5) | 2.4% | — | Kerio Personal Firewall | 31/12/2003 | 16/6/2026 | Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53. | |
| Modificada | Alta (7.5) | 3.9% | — | Cooolsoft Personal FTP Server | 27/5/2003 | 16/6/2026 | Buffer overflow in Personal FTP Server allows remote attackers to execute arbitrary code via a long USER argument. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Kerio Personal Firewall 2 | 12/5/2003 | 16/6/2026 | Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet. | |
| Modificada | Alta (7.5) | 3.8% | — | Kerio Personal Firewall 2 | 12/5/2003 | 16/6/2026 | Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session and replaying them against the remote administration server. | |
| Modificada | Media (6.4) | 1.6% | — | Cooolsoft Personal FTP Server | 31/3/2003 | 16/6/2026 | Directory traversal vulnerability in CooolSoft Personal FTP Server 2.24 allows remote attackers to read or modify arbitrary files via .. (dot dot) sequences in the commands (1) LIST (ls), (2) mkdir, (3) put, or (4) get. | |
| Modificada | Media (5) | 1.3% | — | Cooolsoft Personal FTP Server | 31/3/2003 | 16/6/2026 | CooolSoft Personal FTP Server 2.24 allows remote attackers to obtain the absolute pathname of the FTP root via a PWD command, which includes the full path in the response. | |
| Modificada | Alta (7.5) | 1.5% | — | Symantec Norton Personal Firewall | 31/12/2002 | 16/6/2026 | Symantec Norton Personal Firewall 2002 allows remote attackers to bypass the portscan protection by using a (1) SYN/FIN, (2) SYN/FIN/URG, (3) SYN/FIN/PUSH, or (4) SYN/FIN/URG/PUSH scan. | |
| Modificada | Alta (7.5) | 1.3% | — | Symantec Norton Personal Firewall | 31/12/2002 | 16/6/2026 | The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305). | |
| Modificada | Media (5.5) | 0.25% | — | PGP Personal Privacy | 31/12/2002 | 16/6/2026 | Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message. | |
| Modificada | Alta (10) | 2.2% | — | Symantec Sygate Personal Firewall | 31/12/2002 | 16/6/2026 | Sygate personal firewall 5.0 could allow remote attackers to bypass firewall filters via spoofed (1) source IP address of 127.0.0.1 or (2) network address of 127.0.0.0. | |
| Modificada | Media (5) | 1.6% | — | Kerio Personal Firewall | 31/12/2002 | 16/6/2026 | Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to cause a denial of service (hang and CPU consumption) via a SYN packet flood. | |
| Modificada | Alta (7.5) | 2.0% | — | Atguard Personal Firewall | 31/12/2002 | 16/6/2026 | AtGuard 3.2 allows remote attackers to bypass firwall filters and execute prohibited programs by changing the filenames to permitted filenames. | |
| Modificada | Alta (7.5) | 2.1% | — | PGP Personal Privacy | 31/12/2002 | 16/6/2026 | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Symantec Norton Personal Firewall | 31/12/2002 | 16/6/2026 | Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP addresses and cause a denial of service via spoofed packets. | |
| Modificada | Media (5) | 1.6% | — | Tiny Software Tiny Personal Firewall | 31/12/2002 | 16/6/2026 | Tiny Personal Firewall 3.0 through 3.0.6 allows remote attackers to cause a denial of service (crash) by via SYN, UDP, ICMP and TCP portscans when the administrator selects the Log tab of the Personal Firewall Agent module. | |
| Modificada | Media (5.5) | 0.38% | — | PGP Corporate DesktopPGP FreewarePGP Personal Security | 12/8/2002 | 16/6/2026 | An interaction between PGP 7.0.3 with the "wipe deleted files" option, when used on Windows Encrypted File System (EFS), creates a cleartext temporary files that cannot be wiped or deleted due to strong permissions, which could allow certain local users or attackers with physical access to obtain cleartext information. | |
| Modificada | Alta (7.5) | 3.3% | — | Symantec Norton Internet SecuritySymantec Norton Personal Firewall | 26/7/2002 | 16/6/2026 | Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request. |