Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.9% | 💥 Exploit | Netscape Enterprise ServerSUN Iplanet WEB ServerSUN ONE Application ServerSUN ONE WEB Server | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter. | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft Internet ExplorerMozillaNetscape Navigator | 12/8/2002 | 16/6/2026 | The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted… | |
| Modificada | Media (5) | 1.0% | — | MozillaNetscape Navigator | 25/6/2002 | 16/6/2026 | The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. | |
| Modificada | Media (5) | 2.4% | — | Galeon BrowserMozillaNetscape Navigator | 18/6/2002 | 16/6/2026 | Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. | |
| Modificada | Alta (7.5) | 3.5% | — | MozillaNetscape CommunicatorNetscape Navigator | 18/6/2002 | 16/6/2026 | Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. | |
| Modificada | Baja (2.1) | 0.61% | — | Netscape Communicator | 21/11/2001 | 16/6/2026 | Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext. | |
| Modificada | Media (5) | 1.7% | — | Netscape Messanger | 18/10/2001 | 16/6/2026 | Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property. | |
| Modificada | Media (5) | 1.9% | — | Netscape Collabra Server | 20/9/2001 | 16/6/2026 | Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239. | |
| Modificada | Media (5) | 1.3% | — | Netscape Collabra Server | 20/9/2001 | 16/6/2026 | Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Netscape Publishingxpert | 31/8/2001 | 16/6/2026 | PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter. | |
| Modificada | Alta (7.5) | 8.7% | 💥 Exploit | Netscape Communicator | 2/8/2001 | 16/6/2026 | Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Netscape Smartdownload | 2/7/2001 | 16/6/2026 | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. | |
| Modificada | Alta (7.5) | 2.2% | — | Netscape Directory Server | 2/6/2001 | 16/6/2026 | Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Netscape Enterprise Server | 2/6/2001 | 16/6/2026 | The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command. | |
| Modificada | Media (5) | 2.6% | — | Netscape Enterprise Server | 2/6/2001 | 16/6/2026 | The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command. | |
| Modificada | Media (5) | 1.7% | — | Biblioscape Biblioweb Server | 3/5/2001 | 16/6/2026 | Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request. | |
| Modificada | Media (5) | 1.6% | — | Biblioscape Biblioweb Server | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request. | |
| Modificada | Media (5) | 2.5% | — | Netscape Fasttrack Server | 26/3/2001 | 16/6/2026 | The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs. | |
| Modificada | Alta (10) | 2.2% | — | Netscape Enterprise ServerNetscape Fasttrack ServerNetscape Proxy ServerSCO Unixware | 12/3/2001 | 16/6/2026 | Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges. | |
| Modificada | Media (5) | 1.9% | — | Netscape Enterprise ServerNetscape Fasttrack Server | 12/3/2001 | 16/6/2026 | Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL. | |
| Modificada | Alta (7.5) | 2.6% | — | Netscape CommunicatorNetscape Navigator | 9/1/2001 | 16/6/2026 | Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. | |
| Modificada | Media (5) | 1.7% | — | Netscape Messaging Server | 19/12/2000 | 23/9/2026 | The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse. | |
| Modificada | Alta (10) | 2.4% | — | Netscape Messaging ServerNetscape Messaging Server Multiplexor | 19/12/2000 | 23/9/2026 | Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command. | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Netscape Iplanet Ical | 11/12/2000 | 16/6/2026 | iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse. | |
| Modificada | Alta (10) | 1.6% | — | Netscape Directory ServerSUN Iplanet Certificate Management System | 11/12/2000 | 16/6/2026 | Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server. |