Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.64% | — | HP Openvms | 7/2/2018 | 17/6/2026 | An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha… | |
| Modificada | Media (5) | 2.3% | — | HP TCP IP Services Openvms | 17/12/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the POP implementation in HP OpenVMS TCP/IP 5.7 before ECO5 allow remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 2.4% | — | HP Openvms | 13/12/2012 | 16/6/2026 | HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.49% | — | HP Openvms | 13/12/2012 | 16/6/2026 | HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and ACME_SERVER ACMELOGIN programs, which allows local users to cause a denial of service via unspecified vectors. | |
| Modificada | Media (6.9) | 0.40% | — | Attachmate Reflection FOR HPAttachmate Reflection FOR IBMAttachmate Reflection FOR Regis Graphics ServerAttachmate Reflection FOR Unix AND Openvms+1 | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.9) | 0.39% | — | HP Openvms | 18/5/2012 | 16/6/2026 | The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.9) | 0.44% | — | HP Openvms | 19/4/2012 | 16/6/2026 | Unspecified vulnerability in HP OpenVMS 7.3-2 on the Alpha platform, 8.3 and 8.4 on the Alpha and IA64 platforms, and 8.3-1h1 on the IA64 platform allows local users to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 2.1% | — | HP TCP IP Services Openvms | 7/11/2011 | 16/6/2026 | Unspecified vulnerability in the SMTP service implementation in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 2.0% | — | HP TCP IP Services Openvms | 7/11/2011 | 16/6/2026 | Unspecified vulnerability in the POP and IMAP service implementations in HP TCP/IP Services 5.6 and 5.7 for OpenVMS allows remote attackers to obtain sensitive information via unknown vectors. | |
| Modificada | Media (5.7) | 0.28% | — | HP Openvms | 22/12/2010 | 16/6/2026 | Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via unknown vectors. | |
| Modificada | Media (6.8) | 0.28% | — | HP Openvms | 22/7/2010 | 16/6/2026 | Unspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and earlier on the Itanium platform, allows local users to gain privileges or obtain sensitive information via unknown vectors. | |
| Modificada | Baja (2.1) | 0.47% | — | HP OpenvmsHP Openvms FOR Integrity Servers | 2/7/2010 | 16/6/2026 | Unspecified vulnerability in the HP OpenVMS Auditing feature in OpenVMS ALPHA 7.3-2, 8.2, and 8.3; and OpenVMS for Integrity Servers 8.3 AND 8.3-1H1; allows local users to obtain sensitive information via unknown vectors. | |
| Modificada | Media (6.8) | 0.28% | — | HP Openvms RMS | 4/2/2010 | 16/6/2026 | Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors. | |
| Modificada | Baja (2.1) | 0.44% | — | HP Decnet Plus FOR Openvms | 10/12/2008 | 16/6/2026 | HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services. | |
| Modificada | Alta (10) | 9.9% | — | HP Openvms | 18/11/2008 | 16/6/2026 | Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string. | |
| Modificada | Alta (7.2) | 0.48% | — | HP Openvms | 11/9/2008 | 16/6/2026 | Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of service (crash) or gain privileges via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.44% | — | HP Openvms | 5/9/2008 | 16/6/2026 | DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line. | |
| Modificada | Media (4.9) | 0.56% | — | HP Openvms | 5/9/2008 | 16/6/2026 | The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file. | |
| Modificada | Media (4.4) | 0.38% | — | HP Openvms | 5/9/2008 | 16/6/2026 | Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file. | |
| Modificada | Media (4.3) | 2.1% | — | HP Openvms | 6/10/2007 | 16/6/2026 | Unspecified vulnerability in (1) SYS$EI1000.EXE and (2) SYS$EI1000_MON.EXE in HP OpenVMS 8.3 and earlier allows remote attackers to cause a denial of service (machine crash) via an "oversize" packet, which is not properly discarded if "the device has no remaining buffers after receipt of the first buffer segment." | |
| Modificada | Media (5) | 2.4% | — | HP Openvms | 6/10/2007 | 16/6/2026 | Buffer overflow in NET$CSMACD.EXE in HP OpenVMS 8.3 and earlier allows local users to cause a denial of service (machine crash) via the "MCR MCL SHOW CSMA-CD Port * All" command, which overwrites a Non-Paged Pool Packet. | |
| Modificada | Media (5) | 2.0% | — | HP Openvms | 12/7/2007 | 16/6/2026 | The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 generates different responses depending on whether or not a username is valid, which allows remote attackers to enumerate valid POP usernames. | |
| Modificada | Media (5) | 1.9% | — | HP Openvms | 12/7/2007 | 16/6/2026 | The default configuration of the POP server in TCP/IP Services 5.6 for HP OpenVMS 8.3 does not log the source IP address or attempted username for login attempts, which might help remote attackers to avoid identification. | |
| Modificada | Media (4.9) | 0.49% | — | HP Openvms | 4/6/2007 | 16/6/2026 | The Pascal run-time library (PAS$RTL.EXE) before 20070418 on OpenVMS for Integrity Servers 8.3, and PAS$RTL.EXE before 20070419 on OpenVMS Alpha 8.3, does not properly restore PC and PSL values, which allows local users to cause a denial of service (system crash) via certain Pascal code. | |
| Modificada | Media (4.9) | 0.52% | — | HP Openvms | 2/5/2007 | 16/6/2026 | Unspecified vulnerability in HP OpenVMS for Integrity Servers 8.2-1 and 8.3 allows local users to cause a denial of service (crash) via "Program actions relating to exceptions." |