Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2084 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 22% | — | Oracle Reports | 26/7/2005 | 16/6/2026 | Vulnerabilidad desconocida en Oracle Reports 6.0, 6i, 9i, y 10g permite que atacantes remotos sobreescriban ficheros arbitrarios mediante el parámetro "desname". | |
| Modificada | Media (5) | 9.1% | — | Oracle Reports | 26/7/2005 | 16/6/2026 | Oracle Reports permite que atacantes remotos lean ficheros arbitrarios mediante un path absoluto o relativo a los parámetros CUSTOMIZE o "desformat" de "rwservlet". | |
| Modificada | Media (4.3) | 3.6% | — | Oracle Reports | 26/7/2005 | 16/6/2026 | Múltiples vulnerabilidades de sencuencias de comandos en sitios cruzados en Oracle Reports 9.0.0.2 permite que atacantes remotos inyecten script web arbitrario o HTML mediante 1) el parámetro "debug" a "showenv", 2) el parámetro "test" en "parsequery" o 3)el parámetro "delimiter" o "CELLWRAPPER" en "rwservlet". | |
| Modificada | Baja (2.1) | 0.51% | — | HP Version Control Repository Manager | 29/6/2005 | 16/6/2026 | HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen. | |
| Modificada | Alta (7.5) | 2.0% | — | Redhat SysreportRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation | 13/6/2005 | 16/6/2026 | sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.3% | — | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Bluecoat Reporter | 24/5/2005 | 16/6/2026 | Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license. | |
| Modificada | Media (4.3) | 0.95% | — | Eric Fichot BUG Report | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php. | |
| Modificada | Media (4.3) | 11% | 💥 Exploit | Oracle 10G Reports Server | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Storeportal | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter. | |
| Modificada | Media (4.3) | 20% | — | Microsoft Sharepoint Portal ServerMicrosoft Sharepoint Team Services | 2/5/2005 | 16/6/2026 | Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache. | |
| Modificada | Baja (2.1) | 0.42% | — | Debian Reportbug | 28/2/2005 | 16/6/2026 | reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd. | |
| Modificada | Baja (2.1) | 0.36% | — | Debian Reportbug | 28/2/2005 | 16/6/2026 | reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords. | |
| Modificada | Media (4.3) | 4.8% | 💥 Exploit | Webtrends Reporting Center | 31/12/2004 | 16/6/2026 | viewreport.pl in NetIQ WebTrends Reporting Center Enterprise Edition 6.1a allows remote attackers to determine the installation path via an invalid profileid parameter, which leaks the pathname in an error message. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en los visores web de Business Objects Crystal Reports 9 and 10, y Crystal Enterprise 9 o 10, usados en Visual Studio .NET 2003 y Outlook 2003 con Business Contact Manager, Microsoft Business Solutions CRM 1.2, y otros productos, permiten a atacantes remotos leer y… | |
| Modificada | Media (6.8) | 8.1% | — | Microsoft Sharepoint Portal Server | 4/5/2004 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en Microsoft SharePoint Portal Server 2001 permite a atacantes remotos procesar contenido web elegido arbitrariamente y robar galletitas (cookies) mediante ciertos scripts de servidor. | |
| Modificada | Media (5) | 1.6% | — | Businessobjects Crystal EnterpriseBusinessobjects Crystal Reports | 2/5/2004 | 16/6/2026 | The web interface for Crystal Reports allows remote attackers to cause a denial of service (disk exhaustion) by repeatedly requesting reports without retrieving the associated image files, which are not cleared from the image file folder. | |
| Modificada | Media (6) | 8.2% | — | Microsoft Exchange ServerMicrosoft Sharepoint ServicesMicrosoft Windows Server 2003 | 20/1/2004 | 16/6/2026 | Microsoft Exchange 2003 y Outlook Web Access (OWA), cuando usan SharePoint Services 2.0, hace que la autenticación Kerberos se desactive para IIS, lo que puede causar que usuarios de OWA vean los buzones de correo de otros usuarios. | |
| Modificada | Media (5) | 37% | — | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP | 15/12/2003 | 16/6/2026 | Vulnerabilidad desconocida en el intérprete SmartHTML interpreter (shtml.dll) en Microsoft FrontPage Server Extensions 2000 y 2002, y Microsoft SharePoint Team Services 2002, permite a atacantes remotos causar una denegación de servicio (fallo de respuesta) mediante una cierta petición. | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Microsoft Frontpage Server ExtensionsMicrosoft Sharepoint Team ServicesMicrosoft Windows 2000Microsoft Windows XP | 15/12/2003 | 16/6/2026 | Desbordamiento de búfer en la funcionalidad de depuración en fp30reg.dll de Microsoft FrontPage Server Extensions 2000 y 2002 permite a atacantes remotos ejecutar código mediante una cierta petición en trozos codificada. | |
| Modificada | Alta (7.5) | 2.3% | — | DAG APT Repository MOD Gzip | 17/11/2003 | 16/6/2026 | Vulnerabilidad de cadena de formato en mod_gzip_printf de mod_gzip 1.3.26a y anteriores, y posiblemente versiones oficiales posteriores, cuando corre en modo de depuración y usando el registro de Apache, permite a atacantes remotos ejecutar código arbitrario mediante caractéres de cadena de formato en una petición… | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | DAG APT Repository MOD Gzip | 17/11/2003 | 16/6/2026 | Desbordamiento de búfer basado en la pila en mod_gzip_printf de mod_gzip 1.3.36.1a y anteriores, y posiblemente versiones oficiales posteriores, cuando corre en modo de depuración, permite a atacantes remotos ejecutar código arbitrario mediante un nombre de fichero largo en una petición GET con una cabecera… | |
| Modificada | Alta (7.5) | 6.8% | — | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | La librería de cliente libmysqlclient en MySQL 3.x a 3.23.54 y 4.x a 4.06, no verifica adecuadamente longitudes de campos de ciertas respuestas en las rutinas read_rows o read_one_row, lo que permite a a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Oracle MysqlSymantec Veritas Netbackup Advanced ReporterSymantec Veritas Netbackup Global Data Manager | 23/12/2002 | 16/6/2026 | El comando COM_CHANGE_USER en MySQL 3.x anteriores a 2.23.54 y 4.x anterior a 4.0.6 permite a atacantes remotos ejecutar código arbitrario mediante una respuesta larga. |