Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.16% | — | Veritas Backup Exec | 26/4/2024 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. Improper access controls allow for DLL Hijacking in the Windows DLL Search path. | |
| Analizada | Alta (7.1) | 0.17% | — | Veritas Backup Exec | 26/4/2024 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec Deduplication Multi-threaded Streaming Agent can be leveraged to perform arbitrary file deletion on protected files. | |
| Analizada | Alta (8.8) | 24% | ⚠ Explotación activa | Veritas Backup Exec | 1/3/2021 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access… | |
| Analizada | Crítica (9.8) | 65% | ⚠ Explotación activa | Veritas Backup Exec | 1/3/2021 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 21.2. It supports multiple authentication schemes: SHA authentication is one of these. This authentication scheme is no longer used in current versions of the product, but hadn't yet been disabled. An attacker could remotely exploit this scheme to gain unauthorized… | |
| Analizada | Alta (8.1) | 14% | ⚠ Explotación activa | Veritas Backup Exec | 1/3/2021 | 17/6/2026 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires successful authentication, which is typically completed over a secure TLS communication. However, due to a vulnerability in the SHA Authentication scheme, an attacker is able to gain unauthorized access… | |
| Modificada | Alta (8.8) | 0.46% | — | Veritas Backup Exec | 6/1/2021 | 17/6/2026 | An issue was discovered in the server in Veritas Backup Exec through 16.2, 20.6 before hotfix 298543, and 21.1 before hotfix 657517. On start-up, it loads the OpenSSL library from the Installation folder. This library in turn attempts to load the /usr/local/ssl/openssl.cnf configuration file, which may not exist. On… | |
| Modificada | Media (5.5) | 0.62% | — | Symantec Backup Exec System RecoverySymantec Norton 360Symantec Norton GhostSymantec System Recovery 2011 | 19/2/2018 | 16/6/2026 | GEAR Software CD DVD Filter driver (aka GEARAspiWDM.sys), as used in Symantec Backup Exec System Recovery 8.5 and BESR 2010, Symantec System Recovery 2011, Norton 360, and Norton Ghost, allows local users to cause a denial of service (system crash) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 71% | — | Veritas Backup Exec | 10/5/2017 | 17/6/2026 | In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially… | |
| Modificada | Baja (2.7) | 0.54% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | The NDMP protocol implementation in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote authenticated users to obtain sensitive host-version information via unspecified vectors. | |
| Modificada | Media (4.3) | 0.32% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files. | |
| Modificada | Media (4.3) | 2.0% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allow remote attackers to inject arbitrary web script or HTML via vectors involving a (1) custom-reports generation page, (2) Storage Devices creation page, or (3) jobs creation page in the… | |
| Modificada | Alta (7.9) | 1.5% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | Heap-based buffer overflow in the utility program in the Linux agent in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote attackers to cause a denial of service (agent crash) or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.5) | 1.6% | — | Symantec Backup Exec | 31/5/2011 | 16/6/2026 | Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media server and the remote agent, which allows man-in-the-middle attackers to execute NDMP commands via unspecified vectors. | |
| Modificada | Alta (10) | 11% | — | Symantec Backup Exec Continuous Protection ServerSymantec Veritas Application DirectorSymantec Veritas Backup ExecSymantec Veritas Cluster Server+19 | 11/12/2009 | 16/6/2026 | VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA)… | |
| Modificada | Alta (9) | 4.5% | — | Symantec Backup Exec FOR Windows Server | 10/12/2008 | 16/6/2026 | Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this… | |
| Modificada | Alta (9.4) | 2.6% | — | Symantec Backup Exec FOR Windows Server | 10/12/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors. | |
| Modificada | Media (5.1) | 3.1% | — | Symantec Backup Exec FOR Windows Server | 29/2/2008 | 16/6/2026 | The PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, exposes the unsafe Save method, which allows remote attackers to cause a denial of service (browser crash),… | |
| Modificada | Alta (9.3) | 50% | — | Symantec Backup Exec FOR Windows Server | 29/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1)… | |
| Modificada | Alta (10) | 1.5% | — | Symantec Veritas Backup Exec | 27/9/2007 | 16/6/2026 | Unspecified vulnerability in the client in Symantec Veritas Backup Exec for Windows Servers 11d has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A… | |
| Modificada | Alta (7.5) | 6.9% | — | Symantec Veritas Backup Exec | 12/7/2007 | 16/6/2026 | Heap-based buffer overflow in the RPC subsystem in Symantec Backup Exec for Windows Servers 10.0, 10d, and 11d allows remote attackers to cause a denial of service (process exit) and possibly execute arbitrary code via crafted ncacn_ip_tcp requests. | |
| Modificada | Media (6.5) | 5.8% | — | Symantec Veritas Backup Exec | 14/8/2006 | 16/6/2026 | Multiple heap-based buffer overflows in Symantec VERITAS Backup Exec for Netware Server Remote Agent for Windows Server 9.1 and 9.2 (all builds), Backup Exec Continuous Protection Server Remote Agent for Windows Server 10.1 (builds 10.1.325.6301, 10.1.326.1401, 10.1.326.2501, 10.1.326.3301, and 10.1.327.401), and… | |
| Modificada | Media (4.6) | 1.9% | — | Symantec Veritas Backup Exec | 19/3/2006 | 16/6/2026 | Format string vulnerability in the Job Engine service (bengine.exe) in the Media Server in Veritas Backup Exec 10d (10.1) for Windows Servers rev. 5629, Backup Exec 10.0 for Windows Servers rev. 5520, Backup Exec 10.0 for Windows Servers rev. 5484, and Backup Exec 9.1 for Windows Servers rev. 4691, when the job log… | |
| Modificada | Media (5) | 2.2% | — | Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote Agent | 19/3/2006 | 16/6/2026 | Unspecified vulnerability in Veritas Backup Exec for Windows Server Remote Agent 9.1 through 10.1, for Netware Servers and Remote Agent 9.1 and 9.2, and Remote Agent for Linux Servers 10.0 and 10.1 allow attackers to cause a denial of service (application crash or unavailability) due to "memory errors." | |
| Modificada | Alta (10) | 87% | — | Symantec Veritas Backup ExecSymantec Veritas Backup Exec Remote AgentSymantec Veritas Netbackup | 17/8/2005 | 16/6/2026 | VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for NetWare Media Server Option 4.5 through 5.1 uses a static password during authentication from the NDMP agent to the server, which allows remote attackers to read and write arbitrary files with the… | |
| Modificada | Alta (7.5) | 5.2% | — | Symantec Veritas Backup Exec | 2/8/2005 | 16/6/2026 | Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code. |