Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.5) | 0.57% | — | HPE Icewall Federation AgentAIHPE Icewall ProxyAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). | |
| Pendiente de análisis | Alta (8.8) | 0.30% | — | HPE IcewallAI | 11/9/2026 | 11/9/2026 | A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. | |
| Aplazada | Baja (3.7) | 0.28% | — | HPE IcewallAI | 2/12/2024 | 17/6/2026 | A security vulnerability in HPE IceWall products could be exploited remotely to cause Unauthorized Data Modification. | |
| Aplazada | Media (4.3) | 0.16% | — | HPE Icewall AgentAI | 3/10/2024 | 17/6/2026 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a Cross-Site Request Forgery (CSRF) in the login flow. | |
| Aplazada | Media (6.5) | 0.42% | — | HPE Icewall AgentAI | 26/3/2024 | 17/6/2026 | A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service. | |
| Modificada | Crítica (9.8) | 0.90% | — | HPE Icewall SSO Certd | 8/7/2022 | 17/6/2026 | Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd… | |
| Modificada | Media (6.1) | 0.70% | — | HP Icewall SSO Dgfw | 15/4/2021 | 17/6/2026 | A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | |
| Modificada | Media (6.1) | 0.83% | — | HP Icewall SSO DFWHP Icewall SSO Dgfw | 8/7/2020 | 17/6/2026 | A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess | |
| Modificada | Media (5.9) | 1.7% | — | HP Icewall SSO AgentHP MFA Proxy | 19/7/2019 | 17/6/2026 | A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4… | |
| Modificada | Crítica (9.1) | 1.8% | — | HP Icewall SSO | 6/8/2018 | 17/6/2026 | A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection. | |
| Modificada | Alta (7.5) | 4.0% | — | Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+2 | 30/7/2018 | 17/6/2026 | It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705. | |
| Modificada | Media (4.6) | 0.56% | — | HP Icewall McrpHP Icewall MFAHP Icewall SSO | 15/2/2018 | 17/6/2026 | A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found. | |
| Modificada | Media (6.1) | 1.7% | — | HP Icewall Federation Agent | 15/2/2018 | 17/6/2026 | A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found. | |
| Modificada | Media (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 26/9/2016 | 17/6/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modificada | Crítica (9.8) | 46% | — | HP Icewall Federation AgentHP Icewall McrpHP Icewall SSOHP Icewall SSO Agent Option+2 | 16/9/2016 | 17/6/2026 | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 36% | — | HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+2 | 4/7/2016 | 17/6/2026 | The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. | |
| Modificada | Crítica (9.8) | 45% | — | HP Icewall McrpHP Icewall SSOHP Icewall SSO Agent OptionOpenssl+2 | 20/6/2016 | 17/6/2026 | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and… | |
| Modificada | Crítica (9.8) | 7.0% | — | HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+15 | 9/6/2016 | 17/6/2026 | Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors. | |
| Modificada | Alta (7.5) | 14% | — | HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+7 | 9/6/2016 | 17/6/2026 | The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName. | |
| Modificada | Alta (7.5) | 5.1% | — | Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+2 | 17/5/2016 | 17/6/2026 | The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of… | |
| Modificada | Alta (7.5) | 7.0% | — | Opensuse LeapDebian LinuxHP Icewall Federation AgentHP Icewall File Manager+10 | 17/5/2016 | 17/6/2026 | The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document. | |
| Modificada | Media (5) | 5.9% | — | Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+5 | 15/12/2015 | 17/6/2026 | The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read. | |
| Modificada | Media (5.8) | 4.3% | — | Xmlsoft Libxml2HP Icewall Federation AgentHP Icewall File ManagerApple Iphone OS+8 | 15/12/2015 | 17/6/2026 | The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | |
| Modificada | Media (6.4) | 5.4% | — | Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+5 | 15/12/2015 | 17/6/2026 | The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data. | |
| Modificada | Media (5) | 5.9% | — | HP Icewall Federation AgentHP Icewall File ManagerXmlsoft Libxml2Debian Linux+9 | 15/12/2015 | 17/6/2026 | The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags. |