Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▲ 32 respecto a la semana anterior
Críticas / altas1477▲ 367 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.52%—KdcproxyAI12/11/202530/6/2026
If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery), they can exploit the fact that kdcproxy does not enforce bounds on TCP response length to conduct a denial-of-service attack. While receiving the KDC's response, kdcproxy copies the entire…
AplazadaAlta (8.6)0.46%—KdcproxyAI12/11/202530/6/2026
If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request forgery vulnerability, since an attacker could send a request for a realm matching a…
ModificadaCrítica (9.4)1.3%—Uninett RadsecproxyFedoraproject Fedora28/5/202117/6/2026
radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validation in radsecproxy's `naptr-eduroam.sh` and `radsec-dynsrv.sh` scripts can lead to configuration injection via crafted radsec peer discovery DNS records. Users are subject to Information disclosure,…
ModificadaAlta (7.5)2.2%—Kdcproxy Project Kdcproxy30/10/201817/6/2026
python-kdcproxy before 0.3.2 allows remote attackers to cause a denial of service via a large POST request.
ModificadaMedia (6.4)1.5%—Uninett Radsecproxy20/11/201216/6/2026
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a…
ModificadaMedia (6.4)1.8%—Uninett Radsecproxy20/11/201216/6/2026
radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients.
ModificadaAlta (10)4.8%—Youngzsoft Ccproxy6/3/200916/6/2026
Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname.
ModificadaMedia (5)1.7%—Dircproxy5/10/200716/6/2026
irc_server.c in dircproxy 1.2.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via an ACTION command without a parameter, which triggers a NULL pointer dereference, as demonstrated using a blank /me message from irssi.
ModificadaMedia (6.4)1.9%—Computalynx Cproxy2/5/200516/6/2026
Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.
ModificadaAlta (7.5)11%—Youngzsoft Ccproxy31/12/200416/6/2026
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.
ModificadaAlta (7.5)61%—Youngzsoft Ccproxy31/12/200416/6/2026
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaMedia (5)2.7%—Computalynx Cproxy Server16/5/200016/6/2026
Buffer overflow in CProxy 3.3 allows remote users to cause a denial of service via a long HTTP request.