Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
214 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.64% | — | Mcafee Intrushield Security Management System | 11/7/2005 | 16/6/2026 | McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to… | |
| Modificada | Baja (2.1) | 0.34% | — | Ncipher Nshield | 23/11/2004 | 16/6/2026 | Unknown vulnerability in nCipher Hardware Security Modules (HSM) 1.67.x through 1.99.x allows local users to access secrets stored in the module's run-time memory via certain sequences of commands. | |
| Modificada | Alta (7.5) | 1.3% | — | Ncipher Payshield SPP Library | 17/2/2004 | 16/6/2026 | The SPP_VerifyPVV function in nCipher payShield SPP library 1.3.12, 1.5.18 and 1.6.18 returns a Status_OK value even if the HSM returns a different status code, which could cause applications to make incorrect security-critical decisions, e.g. by accepting an invalid PIN number. | |
| Modificada | Media (4.6) | 0.40% | — | Ncipher NforceNcipher Nshield | 4/10/2002 | 16/6/2026 | The ConsoleCallBack class for nCipher running under JRE 1.4.0 and 1.4.0_01, as used by the TrustedCodeTool and possibly other applications, may leak a passphrase when the user aborts an application that is prompting for the passphrase, which could allow attackers to gain privileges. | |
| Modificada | Alta (7.5) | 6.7% | — | GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+1 | 24/9/2002 | 16/6/2026 | SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")… | |
| Modificada | Alta (7.5) | 2.8% | — | Network Associates Webshield Smtp | 31/12/2001 | 16/6/2026 | NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments. | |
| Modificada | Alta (7.5) | 5.7% | — | Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+1 | 4/9/2001 | 16/6/2026 | Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Network Associates Webshield Smtp | 9/1/2001 | 16/6/2026 | McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field. | |
| Modificada | Alta (7.5) | 1.5% | — | Network Associates Webshield Smtp | 9/1/2001 | 16/6/2026 | McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment. | |
| Modificada | Media (5) | 1.7% | — | Network Associates Webshield Smtp | 20/10/2000 | 16/6/2026 | WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail. | |
| Modificada | Baja (2.1) | 0.43% | — | Network Associates NetshieldNetwork Associates Virusscan | 11/7/2000 | 16/6/2026 | The default installation of VirusScan 4.5 and NetShield 4.5 has insecure permissions for the registry key that identifies the AutoUpgrade directory, which allows local users to execute arbitrary commands by replacing SETUP.EXE in that directory with a Trojan Horse. | |
| Modificada | Alta (10) | 5.9% | 💥 Exploit | Network Associates Gauntlet FirewallNetwork Associates WebshieldNetwork Associates Webshield E-ppliance | 18/5/2000 | 16/6/2026 | Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands. | |
| Modificada | Alta (7.5) | 3.5% | — | Network Associates Webshield | 1/5/2000 | 16/6/2026 | Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service. | |
| Modificada | Media (5) | 2.4% | — | Network Associates Webshield | 1/5/2000 | 16/6/2026 | The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command. |