Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.3%—Decomputeur Toolbar Uninstaller25/8/200916/6/2026
Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website."
ModificadaMedia (6.9)0.35%—Oliver Gorwits Netdisco Mibs Installer8/12/200816/6/2026
netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.
ModificadaMedia (4.4)0.28%—Checkinstall1/7/200816/6/2026
Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.
ModificadaAlta (9.3)8.5%—Microsoft Windows Installer4/6/200816/6/2026
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components…
AnalizadaAlta (9.3)2.2%—Revenera Installshield4/4/200816/6/2026
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
ModificadaAlta (7.5)4.6%💥 ExploitSejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control6/2/200816/6/2026
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
ModificadaAlta (9.3)37%💥 ExploitMacrovision Flexnet ConnectMacrovision Installshield 2008Macrovision Update Service2/11/200716/6/2026
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
ModificadaMedia (4.3)1.8%💥 ExploitOracle Application ServerOracle Rapid Install WEB Server3/7/200716/6/2026
Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the…
ModificadaMedia (4.6)0.32%—Macrovision Installanywhere19/4/200716/6/2026
Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification…
ModificadaAlta (9.3)5.4%—Macrovision Installfromtheweb23/2/200716/6/2026
Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote attackers to execute arbitrary code via crafted HTML documents.
ModificadaMedia (4.6)0.36%—Barron Mccann InstallBarron Mccann X-kryptor DriverBarron Mccann X-kryptor Secure ClientBarron Mccann Xgntr4/2/200716/6/2026
Barron McCann X-Kryptor Driver BMS1446HRR (Xgntr BMS1351 Install BMS1472) in X-Kryptor Secure Client does not drop privileges when launching an Explorer window in response to a help command, which allows local users to gain LocalSystem privileges via interactive use of Explorer.
ModificadaAlta (7.6)18%💥 ExploitApple InstallerApple MAC OS X31/1/200716/6/2026
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a (1) PKG, (2) DISTZ, or (3) MPKG package filename.
ModificadaBaja (1.9)0.42%—Thomas Lange Fully Automated InstallationDebian Linux18/12/200616/6/2026
The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
ModificadaBaja (2.1)0.37%—Bitrock Install BuilderProcess-one Ejabberd5/5/200616/6/2026
A third-party installer generation tool, possibly BitRock InstallBuilder, as used in products including Process-one ejabberd 1.1.1_1 and earlier, generates an installer that allows local users to cause a denial of service via a symlink attack on the bitrock_installer.log temporary file. NOTE: it is possible that this…
ModificadaBaja (1.2)0.30%—Zero G Software InstallanywhereAI31/12/200416/6/2026
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
ModificadaAlta (7.5)1.9%—Mcafee Security Installer Control System31/12/200416/6/2026
An ActiveX control for McAfee Security Installer Control System 4.0.0.81 allows remote attackers to access the Windows registry via web pages that use the control's RegQueryValue() method.
ModificadaBaja (1.2)0.30%—Helix Code Gnome Installer20/10/200016/6/2026
Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.
ModificadaMedia (6.2)0.31%—Helix Code Go-gnome Pre-installer20/10/200016/6/2026
The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.
Orbitaley — Vulnerabilidades