Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authentication and privilege assignment for the guest account, which allows remote attackers to access administrative interfaces or the WLAN. | |
| Modificada | Alta (7.5) | 6.1% | — | Alcatel-lucent Omniaccess WirelessAruba Mobility Controller | 14/2/2007 | 16/6/2026 | Heap-based buffer overflow in the management interfaces in (1) Aruba Mobility Controllers 200, 800, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via long credential strings. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Apple SafariApple WebkitOmnigroup OmniwebApple MAC OS X | 18/1/2007 | 16/6/2026 | WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019. | |
| Modificada | Media (6.8) | 6.4% | 💥 Exploit | Omnigroup Omniweb | 9/1/2007 | 16/6/2026 | Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in the Javascript alert function. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Omniture Sitecatalyst | 19/12/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information. | |
| Modificada | Alta (7.5) | 1.5% | — | Omnistar Interactive Omnistar Article Manager | 15/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in OmniStar Article Manager allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in (a) articles/comments.php and (b) articles/article.php, and the (2) page_id parameter in (c) articles/pages.php. | |
| Modificada | Alta (7.5) | 61% | 💥 Exploit | Xlink Technology Omni-nfs X Enterprise | 7/11/2006 | 16/6/2026 | Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of 20061107, this disclosure has no… | |
| Modificada | Alta (7.5) | 63% | 💥 Exploit | Xlink Technology Omni-nfs Server | 7/11/2006 | 16/6/2026 | Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet to port 2049 (nfsd), as demonstrated by vd_xlink.pm. | |
| Modificada | Alta (7.5) | 1.3% | — | Omnistar Interactive Omnistar Kbase | 29/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Omnistar KBase 4.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter in users/comments.php, (2) category_id and (3) id parameters in users/kb.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Omnistar Interactive Omnistar Live | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240. | |
| Modificada | Media (6.4) | 1.3% | — | Omnipilot Software Lasso Professional Server | 17/8/2005 | 16/6/2026 | Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags. | |
| Modificada | Media (5) | 1.6% | — | Gnome EpiphanyMozilla CaminoMozillaOmnigroup Omniweb+1 | 2/5/2005 | 16/6/2026 | The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. | |
| Modificada | Media (5) | 1.8% | — | Apple SafariHmdt ShiiraOmnigroup Omniweb | 2/5/2005 | 16/6/2026 | AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs. | |
| Modificada | Media (5) | 1.0% | — | Omnigroup Omniweb | 2/5/2005 | 16/6/2026 | The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. | |
| Modificada | Alta (7.5) | 20% | — | Mozilla CaminoMozilla FirefoxMozillaOmnigroup Omniweb+2 | 8/2/2005 | 16/6/2026 | The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing… | |
| Modificada | Media (5) | 1.8% | — | Alcatel OmniswitchAlcatel Omniswitch 7800 | 31/12/2004 | 16/6/2026 | Alcatel OmniSwitch 7000 and 7800 allows remote attackers to cause a denial of service (reboot) via certain network scans, as demonstrated using a Nessus port scan of ports 1 through 1024 with safe-checks disabled. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Omnicron OmnihttpdAI | 31/12/2004 | 16/6/2026 | Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header. | |
| Modificada | Media (5) | 5.0% | — | Alcatel-lucent Omnipcx | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Omnicron Omnihttpd | 9/6/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe. | |
| Modificada | Alta (10) | 3.6% | — | Alcatel-lucent Omnipcx | 31/12/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (5) | 1.6% | — | Omnicron Omnihttpd | 4/10/2002 | 16/6/2026 | Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number. | |
| Modificada | Media (4.6) | 0.31% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. | |
| Modificada | Media (6.2) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file. | |
| Modificada | Baja (2.1) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. | |
| Modificada | Media (5) | 6.3% | 💥 Exploit | Omnicron Omnihttpd | 18/10/2001 | 16/6/2026 | OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20). |