Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.7% | — | SAP Maxdb | 14/8/2018 | 17/6/2026 | SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database. | |
| Modificada | Crítica (9.8) | 1.8% | — | SAP Maxdb Odbc Driver | 9/5/2018 | 17/6/2026 | SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | |
| Modificada | Alta (7.5) | 3.5% | — | SAP GUISAP MaxdbSAP Netweaver Abap Application ServerSAP Netweaver Java Application Server+2 | 2/6/2015 | 17/6/2026 | Stack-based buffer overflow in the LZC decompression implementation (CsObjectInt::CsDecomprLZC function in vpa106cslzc.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent… | |
| Modificada | Media (5) | 2.1% | — | SAP GUISAP MaxdbSAP Netweaver Abap Application ServerSAP Netweaver Java Application Server+2 | 2/6/2015 | 17/6/2026 | The LZH decompression implementation (CsObjectInt::BuildHufTree function in vpa108csulzh.cpp) in SAP MaxDB 7.5 and 7.6, Netweaver Application Server ABAP, Netweaver Application Server Java, Netweaver RFC SDK, GUI, RFC SDK, SAPCAR archive tool, and other products allows context-dependent attackers to cause a denial of… | |
| Modificada | Alta (10) | 15% | — | SAP Maxdb | 29/3/2010 | 16/6/2026 | Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to execute arbitrary code via an invalid length parameter in a handshake packet to TCP port 7210. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.4) | 0.34% | — | SAP Maxdb | 1/8/2008 | 16/6/2026 | Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable. | |
| Modificada | Media (6.9) | 0.37% | — | SAP Maxdb | 11/3/2008 | 16/6/2026 | sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings. | |
| Modificada | Alta (9.3) | 4.0% | — | SAP Maxdb | 11/3/2008 | 16/6/2026 | Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption. | |
| Modificada | Alta (10) | 80% | — | SAP Maxdb | 12/1/2008 | 16/6/2026 | SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe. | |
| Modificada | Alta (10) | 72% | — | Mysql MaxdbSap-db | 30/8/2006 | 16/6/2026 | Buffer overflow in SAP DB and MaxDB before 7.6.00.30 allows remote attackers to execute arbitrary code via a long database name when connecting via a WebDBM client. | |
| Modificada | Media (5) | 1.4% | — | Mysql Maxdb | 2/5/2005 | 16/6/2026 | MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase,… | |
| Modificada | Alta (10) | 4.2% | — | Mysql Maxdb | 26/4/2005 | 16/6/2026 | Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter. | |
| Modificada | Alta (10) | 69% | — | Mysql Maxdb | 25/4/2005 | 16/6/2026 | Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the… | |
| Modificada | Media (5) | 1.4% | — | Mysql Maxdb | 14/4/2005 | 16/6/2026 | The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash. | |
| Modificada | Media (5) | 1.5% | — | Mysql Maxdb | 14/4/2005 | 16/6/2026 | MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via an HTTP request with invalid headers. | |
| Modificada | Alta (7.5) | 3.8% | — | Mysql Maxdb | 13/1/2005 | 16/6/2026 | Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter. | |
| Modificada | Media (5) | 1.4% | — | Mysql Maxdb | 10/1/2005 | 16/6/2026 | MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference. | |
| Modificada | Alta (10) | 4.6% | — | Mysql Maxdb | 10/1/2005 | 16/6/2026 | Stack-based buffer overflow in the WebDav handler in MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to execute arbitrary code via a long Overwrite header. | |
| Modificada | Media (5) | 1.8% | — | Mysql Maxdb | 31/12/2004 | 16/6/2026 | MySQL MaxDB before 7.5.00.18 allows remote attackers to cause a denial of service (crash) via an HTTP request to webdbm with high ASCII values in the Server field, which triggers an assert error in the IsAscii7 function. |