Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2627▼ 298 respecto a la semana anterior
Críticas / altas1348▲ 77 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4) | 0.20% | — | Dracoon Branding ServiceAI | 15/7/2025 | 17/6/2026 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interface with their brand. Versions of the DRACOON Branding Service prior to 2.10.0 are vulnerable to cross-site scripting. Improper neutralization of input from administrative users could inject HTML code… | |
| Modificada | Media (4) | 2.3% | — | Linux Ipsec Tools Racoon Daemon | 13/8/2008 | 16/6/2026 | Memory leak in racoon/proposal.c in the racoon daemon in ipsec-tools before 0.7.1 allows remote authenticated users to cause a denial of service (memory consumption) via invalid proposals. | |
| Modificada | Media (5) | 2.4% | — | Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+3 | 14/3/2005 | 16/6/2026 | The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets. | |
| Modificada | Alta (10) | 5.4% | — | Ipsec-toolsKame RacoonRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 6/12/2004 | 16/6/2026 | The eay_check_x509cert function in KAME Racoon successfully verifies certificates even when OpenSSL validation fails, which could allow remote attackers to bypass authentication. | |
| Modificada | Media (5) | 2.5% | — | Kame Racoon | 14/6/2004 | 16/6/2026 | racoon before 20040407b allows remote attackers to cause a denial of service (infinite loop and dropped connections) via an IKE message with a malformed Generic Payload Header containing invalid (1) "Security Association Next Payload" and (2) "RESERVED" fields. | |
| Modificada | Media (5) | 2.9% | — | Kame Racoon | 1/6/2004 | 16/6/2026 | Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field. | |
| Modificada | Alta (7.5) | 3.6% | — | Kame Racoon | 1/6/2004 | 16/6/2026 | The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate. | |
| Modificada | Media (5) | 6.7% | — | Kame Racoon | 3/3/2004 | 16/6/2026 | KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c. |