Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.8) | 2.3% | — | Alcatel-lucent Omnipcx | 8/3/2011 | 16/6/2026 | Multiple stack-based buffer overflows in unspecified CGI programs in the Unified Maintenance Tool web interface in the embedded web server in the Communication Server (CS) in Alcatel-Lucent OmniPCX Enterprise before R9.0 H1.301.50 allow remote attackers to execute arbitrary code via crafted HTTP headers. | |
| Modificada | Alta (10) | 8.8% | — | Alcatel-lucent Omnipcx Office | 2/4/2008 | 16/6/2026 | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter. | |
| Modificada | Alta (8.5) | 2.4% | — | Alcatel-lucent Omnipcx | 20/11/2007 | 16/6/2026 | The Communication Server in Alcatel-Lucent OmniPCX Enterprise 7.1 and earlier caches an IP address during a TFTP request from an IP Touch phone, and uses this IP address as the destination for all subsequent VoIP packets to this phone, which allows remote attackers to cause a denial of service (loss of audio) or… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa | Al-enterprise Omnipcx Enterprise Communication Server | 18/9/2007 | 16/6/2026 | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. | |
| Modificada | Alta (7.5) | 1.2% | — | Alcatel-lucent Omnipcx | 7/6/2007 | 16/6/2026 | Alcatel-Lucent IP-Touch Telephone running OmniPCX Enterprise 7.0 and later enables the mini switch by default, which allows attackers to gain access to the voice VLAN via daisy-chained systems. | |
| Modificada | Media (5) | 5.0% | — | Alcatel-lucent Omnipcx | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in Alcatel OmniPCX Enterprise 5.0 Lx allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. | |
| Modificada | Alta (10) | 3.6% | — | Alcatel-lucent Omnipcx | 31/12/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs known user accounts and passwords in the /etc/password file by default, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (4.6) | 0.31% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges. | |
| Modificada | Media (6.2) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file. | |
| Modificada | Baja (2.1) | 0.29% | — | Alcatel-lucent Omnipcx | 31/5/2002 | 16/6/2026 | Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system. |