Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 3.0% | — | Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+6 | 14/9/2004 | 16/6/2026 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | MozillaNetscape Navigator | 18/8/2004 | 16/6/2026 | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Netscape Navigator | 6/8/2004 | 16/6/2026 | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack. | |
| Modificada | Alta (7.5) | 1.7% | — | Firebirdsql FirebirdMozillaNetscape Navigator | 27/7/2004 | 16/6/2026 | The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability. | |
| Modificada | Media (5) | 1.2% | — | Mozilla FirefoxNetscape Navigator | 31/12/2003 | 16/6/2026 | Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end. | |
| Modificada | Media (5) | 1.1% | — | Netscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data. | |
| Modificada | Baja (2.1) | 0.39% | — | MozillaNetscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages. | |
| Modificada | Alta (7.6) | 8.7% | 💥 Exploit | Globalscape Cuteftp | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command. | |
| Modificada | Alta (7.5) | 3.9% | — | Globalscape CuteftpAI | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Netscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function. | |
| Modificada | Baja (2.1) | 0.48% | — | Globalscape Cuteftp | 31/12/2003 | 16/6/2026 | Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard. | |
| Modificada | Alta (7.5) | 2.7% | — | Netscape Navigator | 18/8/2003 | 16/6/2026 | Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename. | |
| Modificada | Media (5) | 2.3% | — | Iplanet WEB ServerNetscape Enterprise Server | 31/12/2002 | 16/6/2026 | The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request. | |
| Modificada | Alta (10) | 5.8% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method. | |
| Modificada | Alta (7.5) | 3.5% | — | MozillaNetscape Navigator | 31/12/2002 | 16/6/2026 | Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel. | |
| Modificada | Media (5) | 1.1% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself. | |
| Modificada | Media (4.6) | 1.0% | 💥 Exploit | Netscape Communicator | 31/12/2002 | 16/6/2026 | Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute. | |
| Modificada | Alta (7.5) | 2.6% | — | Iplanet WEB ServerNetscape Enterprise Server | 31/12/2002 | 16/6/2026 | iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection. | |
| Modificada | Alta (7.5) | 1.2% | — | Realityscape Mylogin 2000 | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message. | |
| Modificada | Media (6.4) | 2.0% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes. | |
| Modificada | Media (5) | 1.6% | — | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. | |
| Modificada | Media (5) | 1.3% | — | Netscape Communicator | 29/11/2002 | 16/6/2026 | Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a… | |
| Modificada | Alta (7.5) | 3.7% | — | MozillaNetscape Navigator | 29/11/2002 | 16/6/2026 | Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression. | |
| Modificada | Alta (7.5) | 4.3% | — | MozillaNetscape NavigatorOpera Software Opera WEB Browser | 4/10/2002 | 16/6/2026 | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. |