Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 9.8% | — | Apple WebkitRIM Blackberry Torch 9800 FirmwareRIM Blackberry Torch 9800 | 11/3/2011 | 16/6/2026 | Integer overflow in WebKit, as used on the Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246, in Google Chrome before 10.0.648.133, and in Apple Safari before 5.0.5, allows remote attackers to execute arbitrary code via unknown vectors related to CSS "style handling," nodesets, and a length value,… | |
| Modificada | Media (5) | 0.93% | — | RIM Blackberry Torch 9800 FirmwareRIM Blackberry Torch 9800 | 11/3/2011 | 16/6/2026 | The Research In Motion (RIM) BlackBerry Torch 9800 with firmware 6.0.0.246 allows attackers to read the contents of memory locations via unknown vectors, as demonstrated by Vincenzo Iozzo, Willem Pinckaers, and Ralf-Philipp Weinmann during a Pwn2Own competition at CanSecWest 2011. | |
| Modificada | Media (4.3) | 4.9% | 💥 Exploit | Blackmoonftpserver Blackmoon FTP Server | 20/1/2011 | 16/6/2026 | FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.1737, allows remote attackers to cause a denial of service (crash) via a large number of PORT commands with long arguments, which triggers a NULL pointer dereference. NOTE: some of these details are… | |
| Modificada | Alta (9.3) | 5.7% | — | RIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server Express | 13/1/2011 | 16/6/2026 | Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (4.3) | 1.7% | — | RIM Blackberry Software | 13/1/2011 | 16/6/2026 | Unspecified vulnerability in Research In Motion (RIM) BlackBerry Device Software before 6.0.0 allows remote attackers to cause a denial of service (browser hang) via a crafted web page. | |
| Modificada | Baja (2.1) | 0.36% | — | RIM Blackberry Desktop Software | 17/12/2010 | 16/6/2026 | RIM BlackBerry Desktop Software 4.7 through 6.0 for PC, and 1.0 for Mac, uses a weak password to encrypt a database backup file, which makes it easier for local users to decrypt the file via a brute force attack. | |
| Modificada | Media (6.8) | 2.9% | — | RIM Blackberry Enterprise Server | 17/12/2010 | 16/6/2026 | Multiple buffer overflows in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Enterprise Server 5.0.0 through 5.0.2, 4.1.6, and 4.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF document. | |
| Modificada | Media (6.8) | 2.7% | — | RIM Blackberry Device Software | 14/10/2010 | 16/6/2026 | The browser in Research In Motion (RIM) BlackBerry Device Software 5.0.0.593 Platform 5.1.0.147 on the BlackBerry 9700 does not properly restrict cross-domain execution of JavaScript, which allows remote attackers to bypass the Same Origin Policy via vectors related to a window.open call and an IFRAME element. NOTE:… | |
| Modificada | Alta (7.6) | 3.3% | — | RIM Blackberry Enterprise ServerRIM Blackberry Professional Software | 14/10/2010 | 16/6/2026 | Multiple buffer overflows in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.7 and earlier and 5.0.0 through 5.0.2, and BlackBerry Professional Software 4.1.4 and earlier, allow user-assisted remote attackers to cause a denial of service… | |
| Modificada | Media (4.7) | 0.28% | — | RIM Blackberry Desktop Software | 5/10/2010 | 16/6/2026 | The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via a brute-force attack. | |
| Modificada | Alta (9.3) | 4.7% | — | RIM Blackberry Desktop Software | 15/9/2010 | 16/6/2026 | Untrusted search path vulnerability in BlackBerry Desktop Software before 6.0.0.47 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Blackberry. | |
| Modificada | Baja (2.1) | 0.88% | — | Blackboard Transact Suite | 7/9/2010 | 16/6/2026 | The automated-backup functionality in Blackboard Transact Suite (formerly Blackboard Commerce Suite) stores the (1) database username and (2) database password in cleartext in (a) script and (b) batch (.bat) files, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Media (4.6) | 0.30% | — | Blackboard Transact Suite | 7/9/2010 | 16/6/2026 | BbtsConnection_Edit.exe in Blackboard Transact Suite (formerly Blackboard Commerce Suite) before 3.6.0.2 relies on field names when determining whether it is appropriate to decrypt a connection.xml field value, which allows local users to discover the database password via a modified connection.xml file that contains… | |
| Modificada | Media (6.8) | 0.59% | — | Plainblack Webgui | 26/5/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for unspecified requests via unknown vectors. | |
| Modificada | Alta (9.3) | 4.3% | — | RIM Blackberry Enterprise ServerRIM Blackberry Professional Software | 21/4/2010 | 16/6/2026 | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Systemsoftware Community Black Forum | 9/4/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter. | |
| Modificada | Baja (2.1) | 0.33% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data… | |
| Modificada | Media (4.6) | 0.36% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining… | |
| Modificada | Baja (2.1) | 0.48% | — | Kingston Datatraveler BlackboxKingston Datatraveler EliteKingston Datatraveler Secure | 7/1/2010 | 16/6/2026 | Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive… | |
| Modificada | Media (5) | 1.1% | — | RIM Blackberry BrowserRIM Blackberry 8800 | 16/11/2009 | 16/6/2026 | Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property. | |
| Modificada | Alta (9.3) | 3.9% | — | RIM Blackberry Desktop SoftwareIBM Lotus Notes Intellisync | 4/11/2009 | 16/6/2026 | Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party… | |
| Modificada | Media (6.8) | 0.62% | — | RIM Blackberry Device Software | 29/9/2009 | 16/6/2026 | The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509… | |
| Modificada | Alta (9.3) | 3.6% | — | RIM Blackberry Enterprise ServerRIM Blackberry Professional Software | 30/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or… | |
| Modificada | Alta (9.3) | 5.0% | — | RIM Blackberry Enterprise ServerRIM Blackberry Professional Software | 28/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or… | |
| Modificada | Alta (7.1) | 1.6% | — | RIM Blackberry 8800 | 22/7/2009 | 16/6/2026 | The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption and browser crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692. |