Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.90%—HPE Icewall SSO Certd8/7/202217/6/2026
Security vulnerabilities in HPE IceWall SSO 10.0 certd could be exploited remotely to allow SQL injection or unauthorized data injection. HPE has provided the following updated modules to resolve these vulnerabilities. HPE IceWall SSO version 10.0 certd library Patch 9 for RHEL and HPE IceWall SSO version 10.0 certd…
ModificadaMedia (6.1)0.70%—HP Icewall SSO Dgfw15/4/202117/6/2026
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).
ModificadaMedia (6.1)0.83%—HP Icewall SSO DFWHP Icewall SSO Dgfw8/7/202017/6/2026
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess
ModificadaMedia (5.9)1.7%—HP Icewall SSO AgentHP MFA Proxy19/7/201917/6/2026
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4…
ModificadaCrítica (9.1)1.8%—HP Icewall SSO6/8/201817/6/2026
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
ModificadaMedia (4.6)0.56%—HP Icewall McrpHP Icewall MFAHP Icewall SSO15/2/201817/6/2026
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
ModificadaMedia (5.9)42%—OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+526/9/201617/6/2026
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
ModificadaCrítica (9.8)46%—HP Icewall Federation AgentHP Icewall McrpHP Icewall SSOHP Icewall SSO Agent Option+216/9/201617/6/2026
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
ModificadaAlta (7.5)36%—HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+24/7/201617/6/2026
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
ModificadaCrítica (9.8)45%—HP Icewall McrpHP Icewall SSOHP Icewall SSO Agent OptionOpenssl+220/6/201617/6/2026
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and…
ModificadaMedia (4.3)14%—HP Icewall SSOHP Icewall SSO Agent OptionOpensslOracle VM Virtualbox+96/12/201517/6/2026
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange…
ModificadaMedia (5)3.5%—HP Icewall McrpHP Icewall SSO22/5/201417/6/2026
Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.
ModificadaMedia (4)1.2%—HP Icewall Identity ManagerHP Icewall SSO Password Reset Option5/4/201417/6/2026
Unspecified vulnerability in HP IceWall Identity Manager 4.0 through SP1 and 5.0 and IceWall SSO 10.0 Password Reset Option, when Apache Commons FileUpload is used, allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaBaja (2.1)1.5%—HP Icewall Smart Device OptionHP Icewall SSO AgentHP Icewall SSO Saml2 OptionHP Icewall File Manager+323/9/201316/6/2026
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.0, and IceWall File Manager 3.0 through SP4 allows remote…
ModificadaBaja (3.5)1.00%—HP Icewall SSO Agent Option23/9/201316/6/2026
Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote authenticated users to obtain sensitive information via unknown vectors.
ModificadaMedia (5)3.3%—HP Icewall Smart Device OptionHP Icewall File ManagerHP Icewall SSO AgentHP Icewall SSO Agent Option23/9/201316/6/2026
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, and IceWall File Manager 3.0 through SP4 allows remote attackers to obtain sensitive information via unknown vectors.
ModificadaMedia (5)2.2%—HP Icewall SSO Agent Option23/9/201316/6/2026
Unspecified vulnerability in HP IceWall SSO Agent Option 8.0 through 10.0 allows remote attackers to obtain sensitive information via unknown vectors.