Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.4%—Articatech WEB Proxy25/4/202217/6/2026
There is a Directory Traversal vulnerability in Artica Proxy (4.30.000000 SP206 through SP255, and VMware appliance 4.30.000000 through SP273) via the filename parameter to /cgi-bin/main.cgi.
ModificadaCrítica (9.8)94%—Articatech WEB Proxy12/8/202017/6/2026
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
ModificadaAlta (8.8)82%—Articatech WEB Proxy12/8/202017/6/2026
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
ModificadaAlta (8.8)4.2%—Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+813/3/201617/6/2026
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
ModificadaCrítica (9.8)10%—Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+35/11/201517/6/2026
Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary…
ModificadaMedia (4.3)3.7%—Mozilla Network Security ServicesCanonical Ubuntu LinuxOracle Enterprise Manager OPS CenterOracle Glassfish Communications Server+118/2/201316/6/2026
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical…
ModificadaMedia (5.8)1.5%—Oracle SUN Java System WEB Proxy Server13/7/201016/6/2026
Unspecified vulnerability in Oracle Sun Java System Web Proxy Server 4.0.13 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration Server.
ModificadaMedia (5.4)3.1%—Squid WEB Proxy Cache4/3/200916/6/2026
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that…
ModificadaAlta (10)8.4%—SUN Java System WEB Proxy Server13/10/200816/6/2026
Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.
ModificadaMedia (5)2.5%—SUN Java System WEB Proxy Server14/8/200816/6/2026
Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors.
ModificadaMedia (4.3)2.2%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View URL Database functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 and 3.x before 3.6 SP11 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566309.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Proxy Server 3.6 before SP11 on Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6611356.
ModificadaMedia (4.3)1.9%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in the View Error Log functionality in Sun Java System Web Proxy Server 4.x before 4.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566246.
ModificadaMedia (4.3)1.7%—SUN Java System WEB Proxy ServerSUN Java System WEB Server28/12/200716/6/2026
Cross-site scripting (XSS) vulnerability in Sun Java System Web Server 6.1 before SP8 and 7.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka BugID 6566204.
ModificadaMedia (5)27%—Squid WEB Proxy Cache4/12/200716/6/2026
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
ModificadaAlta (10)26%—SUN Java System WEB Proxy Server29/5/200716/6/2026
Multiple stack-based buffer overflows in the SOCKS proxy support (sockd) in Sun Java Web Proxy Server before 4.0.5 allow remote attackers to execute arbitrary code via crafted packets during protocol negotiation.
ModificadaMedia (6.8)3.6%—SUN Java System Application ServerSUN Java System WEB Proxy ServerSUN Java System WEB ServerSUN ONE Application Server4/12/200616/6/2026
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypass HTTP request filtering, hijack web sessions, perform cross-site scripting (XSS), and poison web caches via unspecified…
ModificadaMedia (5)2.5%—SUN Java System WEB Proxy Server31/12/200516/6/2026
Multiple unspecified vulnerabilities in Sun Java System Web Proxy Server 3.6 SP7 and earlier allow remote attackers to cause a denial of service (unresponsive service) via unknown vectors.
ModificadaAlta (7.5)3.4%—SUN Java System WEB Proxy Server2/5/200516/6/2026
Buffer overflow in Sun Java System Web Proxy Server (aka Sun ONE Proxy Server) 3.6 SP6 allows remote attackers to execute arbitrary code via unknown vectors.
ModificadaMedia (5)3.0%—National Science Foundation Squid WEB Proxy Cache31/12/200416/6/2026
Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer.
ModificadaMedia (5)2.1%—National Science Foundation Squid WEB Proxy Cache31/12/200416/6/2026
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
ModificadaAlta (7.5)7.7%—SUN Java System WEB Proxy Server30/10/200416/6/2026
Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests.
ModificadaAlta (10)71%—National Science Foundation Squid WEB Proxy Cache6/8/200416/6/2026
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).
ModificadaMedia (5)2.8%—Squid WEB Proxy6/12/200116/6/2026
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.
ModificadaAlta (7.5)2.0%—Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+418/7/200116/6/2026
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.