Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2558▼ 318 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.3)0.48%—Totalwebshield Total Webshield9/8/202517/6/2026
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unknown part of the component Block Page. The manipulation of the argument Category leads to cross site scripting. It is possible to initiate the attack remotely. The…
ModificadaAlta (7.2)0.75%—Kingsoft Webshield24/5/201016/6/2026
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.
ModificadaAlta (10)6.1%—Mcafee Webshield Smtp4/4/200616/6/2026
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce message is constructed.
ModificadaAlta (7.5)6.7%—GFI MailsecurityNetwork Associates Webshield SmtpRoaring Penguin CanitRoaring Penguin Mimedefang+124/9/200216/6/2026
SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefang before 2.21, and possibly other products, do not detect fragmented emails as defined in RFC2046 ("Message Fragmentation and Reassembly")…
ModificadaAlta (7.5)2.8%—Network Associates Webshield Smtp31/12/200116/6/2026
NAI WebShield SMTP 4.5 and possibly 4.5 MR1a does not filter improperly MIME encoded email attachments, which could allow remote attackers to bypass filtering and possibly execute arbitrary code in email clients that process the invalid attachments.
ModificadaAlta (7.5)5.7%—Mcafee Webshield SmtpNetwork Associates Gauntlet FirewallPGP E-ppliance 300SGI Irix+14/9/200116/6/2026
Buffer overflow in the (1) smap/smapd and (2) CSMAP daemons for Gauntlet Firewall 5.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted mail message.
ModificadaMedia (5)2.5%—Network Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
ModificadaAlta (7.5)1.5%—Network Associates Webshield Smtp9/1/200116/6/2026
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.
ModificadaMedia (5)1.7%—Network Associates Webshield Smtp20/10/200016/6/2026
WebShield SMTP 4.5 allows remote attackers to cause a denial of service by sending e-mail with a From: address that has a . (period) at the end, which causes WebShield to continuously send itself copies of the e-mail.
ModificadaAlta (10)5.9%—Network Associates Gauntlet FirewallNetwork Associates WebshieldNetwork Associates Webshield E-ppliance18/5/200016/6/2026
Buffer overflow in the CyberPatrol daemon "cyberdaemon" used in gauntlet and WebShield allows remote attackers to cause a denial of service or execute arbitrary commands.
ModificadaAlta (7.5)3.5%—Network Associates Webshield1/5/200016/6/2026
Buffer overflow in WebShield SMTP 4.5.44 allows remote attackers to execute arbitrary commands via a long configuration parameter to the WebShield remote management service.
ModificadaMedia (5)2.4%—Network Associates Webshield1/5/200016/6/2026
The WebShield SMTP Management Tool version 4.5.44 does not properly restrict access to the management port when an IP address does not resolve to a hostname, which allows remote attackers to access the configuration via the GET_CONFIG command.