Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.9%💥 ExploitNetscape Enterprise ServerSUN Iplanet WEB ServerSUN ONE Application ServerSUN ONE WEB Server4/10/200216/6/2026
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.
ModificadaAlta (7.5)3.7%—Microsoft Internet ExplorerMozillaNetscape Navigator12/8/200216/6/2026
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted…
ModificadaMedia (5)1.0%—MozillaNetscape Navigator25/6/200216/6/2026
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.
ModificadaMedia (5)2.4%—Galeon BrowserMozillaNetscape Navigator18/6/200216/6/2026
Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect.
ModificadaAlta (7.5)3.5%—MozillaNetscape CommunicatorNetscape Navigator18/6/200216/6/2026
Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI.
ModificadaBaja (2.1)0.61%—Netscape Communicator21/11/200116/6/2026
Netscape 4.79 and earlier for MacOS allows an attacker with access to the browser to obtain passwords from form fields by printing the document into which the password has been typed, which is printed in cleartext.
ModificadaMedia (5)1.7%—Netscape Messanger18/10/200116/6/2026
Netscape 4.7x allows remote attackers to obtain sensitive information such as the user's login, mailbox location and installation path via Javascript that accesses the mailbox: URL in the document.referrer property.
ModificadaMedia (5)1.9%—Netscape Collabra Server20/9/200116/6/2026
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.
ModificadaMedia (5)1.3%—Netscape Collabra Server20/9/200116/6/2026
Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.
ModificadaMedia (5)3.8%💥 ExploitNetscape Publishingxpert31/8/200116/6/2026
PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying the target file in the errPagePath parameter.
ModificadaAlta (7.5)8.7%💥 ExploitNetscape Communicator2/8/200116/6/2026
Netscape Communicator before 4.77 allows remote attackers to execute arbitrary Javascript via a GIF image whose comment contains the Javascript.
ModificadaAlta (7.5)7.5%💥 ExploitNetscape Smartdownload2/7/200116/6/2026
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
ModificadaAlta (7.5)2.2%—Netscape Directory Server2/6/200116/6/2026
Buffer overflow in Netscape Directory Server 4.12 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed recipient field.
ModificadaMedia (5)3.4%💥 ExploitNetscape Enterprise Server2/6/200116/6/2026
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.
ModificadaMedia (5)2.6%—Netscape Enterprise Server2/6/200116/6/2026
The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.
ModificadaMedia (5)1.7%—Biblioscape Biblioweb Server3/5/200116/6/2026
Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.
ModificadaMedia (5)1.6%—Biblioscape Biblioweb Server3/5/200116/6/2026
Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.
ModificadaMedia (5)2.5%—Netscape Fasttrack Server26/3/200116/6/2026
The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.
ModificadaAlta (10)2.2%—Netscape Enterprise ServerNetscape Fasttrack ServerNetscape Proxy ServerSCO Unixware12/3/200116/6/2026
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and 2.1.3 allow an attacker to gain root privileges.
ModificadaMedia (5)1.9%—Netscape Enterprise ServerNetscape Fasttrack Server12/3/200116/6/2026
Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.
ModificadaAlta (7.5)2.6%—Netscape CommunicatorNetscape Navigator9/1/200116/6/2026
Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field.
ModificadaMedia (5)1.7%—Netscape Messaging Server19/12/200023/9/2026
The POP3 server in Netscape Messaging Server 4.15p1 generates different error messages for incorrect user names versus incorrect passwords, which allows remote attackers to determine valid users on the system and harvest email addresses for spam abuse.
ModificadaAlta (10)2.4%—Netscape Messaging ServerNetscape Messaging Server Multiplexor19/12/200023/9/2026
Buffer overflow in IMAP server in Netscape Messaging Server 4.15 Patch 2 allows local users to execute arbitrary commands via a long LIST command.
ModificadaAlta (7.2)1.1%💥 ExploitNetscape Iplanet Ical11/12/200016/6/2026
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal configuration and execute arbitrary commands by replacing the iplncal.sh program with a Trojan horse.
ModificadaAlta (10)1.6%—Netscape Directory ServerSUN Iplanet Certificate Management System11/12/200016/6/2026
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.