Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)3.0%—Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+614/9/200416/6/2026
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
ModificadaAlta (10)13%💥 ExploitMozillaNetscape Navigator18/8/200416/6/2026
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
ModificadaMedia (5)2.3%💥 ExploitNetscape Navigator6/8/200416/6/2026
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
ModificadaAlta (7.5)1.7%—Firebirdsql FirebirdMozillaNetscape Navigator27/7/200416/6/2026
The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
ModificadaMedia (5)1.2%—Mozilla FirefoxNetscape Navigator31/12/200316/6/2026
Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.
ModificadaMedia (5)1.1%—Netscape Navigator31/12/200316/6/2026
Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.
ModificadaBaja (2.1)0.39%—MozillaNetscape Navigator31/12/200316/6/2026
Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages.
ModificadaAlta (7.6)8.7%💥 ExploitGlobalscape Cuteftp31/12/200316/6/2026
Buffer overflow in CuteFTP 5.0 allows remote attackers to execute arbitrary code via a long response to a LIST command.
ModificadaAlta (7.5)3.9%—Globalscape CuteftpAI31/12/200316/6/2026
Buffer overflow in CuteFTP 4.2 and 5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long FTP server banner.
ModificadaMedia (4.3)2.1%💥 ExploitNetscape Navigator31/12/200316/6/2026
Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function.
ModificadaBaja (2.1)0.48%—Globalscape Cuteftp31/12/200316/6/2026
Buffer overflow in CuteFTP 5.0 and 5.0.1 allows local users to cause a denial of service (crash) by copying a long URL into a clipboard.
ModificadaAlta (7.5)2.7%—Netscape Navigator18/8/200316/6/2026
Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename.
ModificadaMedia (5)2.3%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial of service (crash) via a wp-html-rend request.
ModificadaAlta (10)5.8%—Netscape Communicator31/12/200216/6/2026
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.
ModificadaAlta (7.5)3.5%—MozillaNetscape Navigator31/12/200216/6/2026
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
ModificadaMedia (5)1.1%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
ModificadaMedia (4.6)1.0%💥 ExploitNetscape Communicator31/12/200216/6/2026
Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute.
ModificadaAlta (7.5)2.6%—Iplanet WEB ServerNetscape Enterprise Server31/12/200216/6/2026
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Authentication via the wp-force-auth Web Publisher command, which provides a distinct attack vector and may make it easier to conduct brute force password guessing without detection.
ModificadaAlta (7.5)1.2%—Realityscape Mylogin 200031/12/200216/6/2026
SQL injection vulnerability in RealityScape MyLogin 2000 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) Username or (2) Password in the login form.
ModificadaMedia (5)3.9%💥 ExploitMozillaNetscape CommunicatorNetscape Navigator31/12/200216/6/2026
The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message.
ModificadaMedia (6.4)2.0%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
ModificadaMedia (5)1.6%—MozillaNetscape CommunicatorNetscape Navigator31/12/200216/6/2026
Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.
ModificadaMedia (5)1.3%—Netscape Communicator29/11/200216/6/2026
Netscape Communicator 4.x allows attackers to use a link to steal a user's preferences, including potentially sensitive information such as URL history, e-mail address, and possibly the e-mail password, by redefining the user_pref() function and accessing the prefs.js file, which is stored in a directory with a…
ModificadaAlta (7.5)3.7%—MozillaNetscape Navigator29/11/200216/6/2026
Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression.
ModificadaAlta (7.5)4.3%—MozillaNetscape NavigatorOpera Software Opera WEB Browser4/10/200216/6/2026
Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width.