Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3238▲ 694 respecto a la semana anterior
Críticas / altas1520▲ 133 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2412 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Archive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+19 | 27/1/2005 | 16/6/2026 | RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | |
| Modificada | Media (5) | 2.3% | — | PHP Arena Pafiledb | 10/1/2005 | 16/6/2026 | paFileDB 3.1, when using sessions authentication and while the administrator logs on, allows remote attackers to read the administrator's password hash and conduct brute force password guessing attacks by listing the contents of the sessions directory and reading the associated file for the administrator session. | |
| Modificada | Alta (7.5) | 19% | 💥 Exploit | Broadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus GatewayBroadcom Etrust EZ Antivirus+18 | 10/1/2005 | 16/6/2026 | El módulo Perl Archive::Zip anterior a 1.14, cuando se usa en programas antivirus como amavisd-new, permite a atacantes remotos saltarse la protección del antivirus mediante un ficheros comprimido con cabeceras globales y locales establecido a cero, lo que no impide que el fichero comprimido sea abierto en un sistema… | |
| Modificada | Alta (10) | 11% | 💥 Exploit | FileGentoo LinuxTrustix Secure Linux | 10/1/2005 | 16/6/2026 | Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file. | |
| Modificada | Alta (10) | 6.0% | — | Dxfscope DXF File Format Viewer | 10/1/2005 | 16/6/2026 | Buffer overflow in the dxfin function in d.c for dxfscope 0.2 allows remote attackers to execute arbitrary code via a crafted DXF file. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Solarwinds Serv-u File Server | 31/12/2004 | 16/6/2026 | Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command. | |
| Modificada | Alta (7.8) | 4.1% | 💥 Exploit | Fastream Netfile Server | 31/12/2004 | 16/6/2026 | Fastream NETFile Server 7.1.2 does not properly handle keep-alive connection timeouts and does not close the connection after a HEAD request, which allows remote attackers to perform a denial of service (connection consumption) by sending a large number HTTP HEAD requests. | |
| Modificada | Alta (8.5) | 87% | 💥 Exploit | Solarwinds Serv-u File Server | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | DSM Light WEB File Browser | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter. | |
| Modificada | Media (4.3) | 2.6% | 💥 Exploit | PHP Arena Pafiledb | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the (1) email or (2) file modules in paFileDB 3.1 Final allows remote attackers to execute arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (5) | 3.0% | — | Solarwinds Serv-u File Server | 31/12/2004 | 16/6/2026 | Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111. | |
| Modificada | Alta (10) | 85% | 💥 Exploit | Solarwinds Serv-u File Server | 23/11/2004 | 16/6/2026 | Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command. | |
| Modificada | Media (5) | 12% | 💥 Exploit | Solarwinds Serv-u File Server | 11/9/2004 | 16/6/2026 | Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX. | |
| Modificada | Alta (10) | 4.3% | 💥 Exploit | Fastream Netfile FTP WEB Server | 6/8/2004 | 16/6/2026 | Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter. | |
| Modificada | Media (5) | 1.2% | — | Fastream Netfile FTP WEB Server | 6/8/2004 | 16/6/2026 | Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A"). | |
| Modificada | Alta (7.5) | 2.5% | — | Snapfiles Whisper FTP Surfer | 27/7/2004 | 16/6/2026 | Desbordamiento de búfer en el Whisper FTP Surfer 1.0.7 permite a servidores FTP remotos causar una denegación de servicio (cáida de cliente) y posiblemente ejecutar código de su elección mediante un nombre de fichero largo. | |
| Modificada | Media (5) | 1.3% | — | Lionmax Software WWW File Share PRO | 27/7/2004 | 16/6/2026 | LionMax Software WWW File Share Pro 2.60 permite a atacantes remotos causar una denegación de servicio (caída o cuelgue) mediante una URL larga, posiblemente disparando un desbordamiento de búfer. | |
| Modificada | Media (5) | 8.2% | 💥 Exploit | Easyweb Filemanager | 23/7/2004 | 16/6/2026 | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter. | |
| Modificada | Media (5) | 1.2% | — | PHP Arena Pafiledb | 27/4/2004 | 16/6/2026 | paFileDB 3.1 allows remote attackers to gain sensitive information via a direct request to (1) login.php, (2) category.php, (3) search.php, (4) main.php, (5) viewall.php, (6) download.php, (7) email.php, (8) file.php, (9) rate.php, or (10) stats.php, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | PHP Arena Pafiledb | 27/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the category module in pafiledb.php for paFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a vulnerability that is closely related to CVE-2004-1551. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Solarwinds Serv-u File Server | 20/4/2004 | 16/6/2026 | Buffer overflow in Serv-U FTP server before 5.0.0.6 allows remote attackers to cause a denial of service (crash) via a long -l parameter, which triggers an out-of-bounds read. | |
| Modificada | Media (5) | 2.0% | — | Fastream Netfile FTP WEB Server | 19/4/2004 | 16/6/2026 | Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist. | |
| Modificada | Media (5) | 1.3% | — | Lionmax Software WWW File Share PRO | 17/2/2004 | 16/6/2026 | WWW File Share Pro 2.42 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición POST muy grande. |