Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 30% | — | Microsoft Distributed Transaction CoordinatorMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows NT+1 | 10/5/2006 | 16/6/2026 | Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the… | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (5) | 1.6% | — | Xampp Apache Distribution | 17/6/2005 | 16/6/2026 | Directory traversal vulnerability in XAMPP before 1.4.14 allows remote attackers to inject arbitrary HTML and PHP code via lang.php. | |
| Modificada | Alta (7.5) | 1.3% | — | Distinct WEB Creations Newsletterez | 25/5/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Xampp Apache Distribution | 12/4/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Xampp Apache Distribution | 12/4/2005 | 16/6/2026 | XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges. | |
| Modificada | Media (5) | 1.6% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | |
| Modificada | Media (5) | 3.2% | — | Cisco Application AND Content Networking SoftwareCisco Content Delivery ManagerCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650+6 | 24/2/2005 | 16/6/2026 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Alta (7.5) | 2.4% | — | CA Unicenter WEB Services Distributed ManagementIBM Trading Partner InterchangeJetty Http Server | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 1.6% | — | Distcc | 23/12/2004 | 16/6/2026 | distcc anteriores a 2.16, cuando se ejecutan en plataformas de 64 bits, no interpreta reglas de control de acceso basadas en IP correctamente, lo que podría permitir a atacantes remotos sortear las restricciones pretendidas. | |
| Modificada | Alta (7.5) | 4.4% | — | Cisco Application AND Content Networking SoftwareCisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content Distribution Manager 4670+5 | 5/1/2004 | 16/6/2026 | Desbordamiento de búfer en el módulo de autenticación de Cisco ACNS 4.x anteriores a 4.2.11, y 5.x anteriores a 5.0.5, permite a atacantes remotos ejecutar código arbitrario mediante una contraseña larga. | |
| Modificada | Alta (7.8) | 0.65% | — | Distrotech CVS | 12/8/2002 | 16/6/2026 | Off-by-one overflow in the CVS PreservePermissions of rcs.c for CVSD before 1.11.2 allows local users to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Content Distribution Manager 4630Cisco Content Distribution Manager 4650Cisco Content EngineCisco Enterprise Content Delivery Network Software+4 | 12/8/2002 | 16/6/2026 | The default configuration of the proxy for Cisco Cache Engine and Content Engine allows remote attackers to use HTTPS to make TCP connections to allowed IP addresses while hiding the actual source IP. | |
| Modificada | Media (5) | 2.4% | — | Cisco Catalyst 2900xlCisco Catalyst 2948g-l3Cisco Catalyst 2950Cisco Catalyst 3500xl+7 | 15/11/2001 | 16/6/2026 | Multiple Cisco networking products allow remote attackers to cause a denial of service on the local network via a series of ARP packets sent to the router's interface that contains a different MAC address for the router, which eventually causes the router to overwrite the MAC address in its ARP table. | |
| Modificada | Media (4.6) | 0.34% | — | Transarc DCE Distributed File System | 17/9/1996 | 16/6/2026 | Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS. |