Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

237 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.3%—Alcatel-lucent Omniaccess WirelessAruba Mobility Controller14/2/200716/6/2026
The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN.
ModificadaAlta (7.5)6.1%—Alcatel-lucent Omniaccess WirelessAruba Mobility Controller14/2/200716/6/2026
Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings.
ModificadaAlta (7.5)2.3%💥 ExploitApple SafariApple WebkitOmnigroup OmniwebApple MAC OS X18/1/200716/6/2026
WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.
ModificadaMedia (6.8)6.4%💥 ExploitOmnigroup Omniweb9/1/200716/6/2026
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function.
ModificadaMedia (6.8)2.0%💥 ExploitOmniture Sitecatalyst19/12/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.
ModificadaAlta (7.5)1.5%—Omnistar Interactive Omnistar Article Manager15/11/200616/6/2026
Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php.
ModificadaAlta (7.5)61%💥 ExploitXlink Technology Omni-nfs X Enterprise7/11/200616/6/2026
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of 20061107, this disclosure has no…
ModificadaAlta (7.5)63%💥 ExploitXlink Technology Omni-nfs Server7/11/200616/6/2026
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm.
ModificadaAlta (7.5)1.3%—Omnistar Interactive Omnistar Kbase29/11/200516/6/2026
Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php.
ModificadaAlta (7.5)1.2%—Omnistar Interactive Omnistar Live26/11/200516/6/2026
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240.
ModificadaMedia (6.4)1.3%—Omnipilot Software Lasso Professional Server17/8/200516/6/2026
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
ModificadaMedia (5)1.6%—Gnome EpiphanyMozilla CaminoMozillaOmnigroup Omniweb+12/5/200516/6/2026
The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
ModificadaMedia (5)1.8%—Apple SafariHmdt ShiiraOmnigroup Omniweb2/5/200516/6/2026
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.
ModificadaMedia (5)1.0%—Omnigroup Omniweb2/5/200516/6/2026
The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
ModificadaAlta (7.5)20%—Mozilla CaminoMozilla FirefoxMozillaOmnigroup Omniweb+28/2/200516/6/2026
The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing…
ModificadaMedia (5)1.8%—Alcatel OmniswitchAlcatel Omniswitch 780031/12/200416/6/2026
Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled.
ModificadaAlta (7.5)10%💥 ExploitOmnicron OmnihttpdAI31/12/200416/6/2026
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.
ModificadaMedia (5)5.0%—Alcatel-lucent Omnipcx31/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaMedia (4.3)3.9%💥 ExploitOmnicron Omnihttpd9/6/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
ModificadaAlta (10)3.6%—Alcatel-lucent Omnipcx31/12/200216/6/2026
Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access.
ModificadaMedia (5)1.6%—Omnicron Omnihttpd4/10/200216/6/2026
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
ModificadaMedia (4.6)0.31%—Alcatel-lucent Omnipcx31/5/200216/6/2026
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.
ModificadaMedia (6.2)0.29%—Alcatel-lucent Omnipcx31/5/200216/6/2026
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.
ModificadaBaja (2.1)0.29%—Alcatel-lucent Omnipcx31/5/200216/6/2026
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.
ModificadaMedia (5)6.3%💥 ExploitOmnicron Omnihttpd18/10/200116/6/2026
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).
Orbitaley — Vulnerabilidades