Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.9%—Broadcom Symantec Messaging Gateway26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 10.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
ModificadaCrítica (9.8)1.6%—Broadcom Symantec Messaging Gateway26/1/202417/6/2026
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
ModificadaMedia (5.4)1.5%—Symantec Messaging Gateway9/12/202217/6/2026
An authenticated user can embed malicious content with XSS into the admin group policy page.
ModificadaMedia (5.4)0.39%—Symantec Messaging Gateway9/12/202217/6/2026
An authenticated user who has the privilege to add/edit annotations on the Content tab, can craft a malicious annotation that can be executed on the annotations page (Annotation Text Column).
ModificadaMedia (4.9)0.73%—Broadcom Symantec Messaging Gateway24/6/202217/6/2026
A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that they might not otherwise be authorized to access.
ModificadaMedia (4.9)0.87%—Broadcom Symantec Messaging Gateway10/12/202017/6/2026
An information disclosure flaw allows a malicious, authenticated, privileged web UI user to obtain a password for a remote SCP backup server that they might not otherwise be authorized to access. This affects SMG prior to 10.7.4.
ModificadaAlta (7.2)1.5%—Broadcom Symantec Messaging Gateway10/12/202017/6/2026
A privilege escalation flaw allows a malicious, authenticated, privileged CLI user to escalate their privileges on the system and gain full control over the SMG appliance. This affects SMG prior to 10.7.4.
ModificadaAlta (8.8)1.4%—Microfocus Secure Messaging Gateway7/8/202017/6/2026
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key information to inject system commands into the call to the DKIM system command.
ModificadaAlta (7.8)8.1%—IBM DominoIBM NotesSymantec Data Loss Prevention EndpointSymantec Data Loss Prevention Enforce/detection Servers+321/2/202016/6/2026
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus…
ModificadaAlta (7.3)1.1%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a server-side request forgery (SSRF) exploit, which is a type of issue that can let an attacker send crafted requests from the backend server of a vulnerable web application or access services available through the loopback interface.
ModificadaMedia (4.8)0.73%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a cross-site scripting (XSS) exploit, which is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to potentially bypass access…
ModificadaAlta (7.2)1.4%—Symantec Messaging Gateway11/12/201917/6/2026
Symantec Messaging Gateway, prior to 10.7.3, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
ModificadaMedia (4.5)0.48%—Symantec Messaging Gateway24/10/201917/6/2026
Symantec Messaging Gateway (prior to 10.7.0), may be susceptible to an information disclosure issue, which is a type of vulnerability that could potentially allow unauthorized access to data.
ModificadaAlta (8.8)0.77%—Symantec Messaging Gateway19/9/201817/6/2026
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML input containing a reference to an external entity is processed by a weakly configured XML parser. The attack uses file URI schemes or relative paths in the system…
ModificadaCrítica (9.8)3.0%—Symantec Messaging Gateway19/9/201817/6/2026
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to an authentication bypass exploit, which is a type of issue that can allow attackers to potentially circumvent security mechanisms currently in place and gain access to the system or network.
ModificadaAlta (7.2)80%—Microfocus Secure Messaging Gateway29/6/201817/6/2026
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated…
ModificadaCrítica (9.8)81%—Microfocus Secure Messaging Gateway29/6/201817/6/2026
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with…
ModificadaMedia (5.7)1.4%—Symantec Messaging Gateway20/12/201717/6/2026
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to access arbitrary files and directories…
ModificadaCrítica (10)73%—Symantec Messaging Gateway26/6/201717/6/2026
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process.
ModificadaMedia (6.6)2.5%—Symantec Messaging Gateway26/6/201717/6/2026
The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path to executable code using an attacker-controlled variable in a…
ModificadaAlta (7.3)1.3%—Symantec Messaging Gateway26/6/201717/6/2026
The Symantec Messaging Gateway, when processing a specific email attachment, can allow a malformed or corrupted Word file with a potentially malicious macro through despite the administrator having the 'disarm' functionality enabled. This constitutes a 'bypass' of the disarm functionality resident to the application.
ModificadaMedia (6.5)54%—Symantec Messaging Gateway14/4/201717/6/2026
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
ModificadaMedia (5.5)5.3%—Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+1114/4/201717/6/2026
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaMedia (5.5)6.9%—Broadcom Symantec Data Center Security ServerSymantec Advanced Threat ProtectionSymantec CsapiSymantec Email Security.cloud+1114/4/201717/6/2026
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint…
ModificadaAlta (8.2)0.67%—Symantec Messaging Gateway22/4/201617/6/2026
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.