Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.49% | — | Netscape Iplanet Ical | 11/12/2000 | 16/6/2026 | csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory. | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Netscape Directory ServerSUN Iplanet Certificate Management System | 11/12/2000 | 16/6/2026 | Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services. | |
| Modificada | Alta (10) | 3.0% | — | Netscape Iplanet Ical | 11/12/2000 | 16/6/2026 | The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges. | |
| Modificada | Alta (10) | 4.1% | 💥 Exploit | Netscape Iplanet Ical | 11/12/2000 | 23/9/2026 | csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory. | |
| Modificada | Alta (7.5) | 34% | 💥 Exploit | Microsoft Virtual MachineNetscape Communicator | 20/10/2000 | 16/6/2026 | Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice. | |
| Modificada | Media (5) | 20% | 💥 Exploit | Netscape Communicator | 20/10/2000 | 16/6/2026 | Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice. | |
| Modificada | Media (5) | 13% | 💥 Exploit | MozillaNetscape Communicator | 25/7/2000 | 16/6/2026 | Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1. | |
| Modificada | Alta (7.5) | 2.4% | — | Netscape Enterprise ServerNovell Netware | 26/6/2000 | 16/6/2026 | Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL. | |
| Modificada | Alta (10) | 4.5% | 💥 Exploit | Netscape Professional Services Ftpserver | 21/6/2000 | 16/6/2026 | Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.3% | — | Netscape Communicator | 26/5/2000 | 16/6/2026 | Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information. | |
| Modificada | Baja (2.6) | 1.0% | — | Netscape Communicator | 10/5/2000 | 16/6/2026 | Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability. | |
| Modificada | Baja (3.7) | 0.31% | 💥 Exploit | Netscape Communicator | 10/5/2000 | 16/6/2026 | Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate. | |
| Modificada | Baja (2.6) | 1.0% | — | Netscape Communicator | 1/4/2000 | 16/6/2026 | A remote attacker can read information from a Netscape user's cache via JavaScript. | |
| Modificada | Media (5) | 5.9% | 💥 Exploit | Netscape Enterprise Server | 17/3/2000 | 16/6/2026 | Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump. | |
| Modificada | Media (6.4) | 2.1% | — | Netscape Enterprise Server | 11/3/2000 | 16/6/2026 | Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories. | |
| Modificada | Media (5) | 0.78% | — | Netscape Communicator | 12/1/2000 | 16/6/2026 | Netscape Navigator uses weak encryption for storing a user's Netscape mail password. | |
| Modificada | Media (5) | 1.3% | — | Netscape CommunicatorNetscape Navigator | 12/1/2000 | 16/6/2026 | Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. | |
| Modificada | Media (5) | 0.88% | — | Globalscape Cuteftp | 6/1/2000 | 16/6/2026 | CuteFTP uses weak encryption to store password information in its tree.dat file. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Netscape Enterprise ServerNetscape Fasttrack Server | 4/1/2000 | 16/6/2026 | Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request. | |
| Modificada | Media (4.6) | 0.40% | — | Netscape Communicator | 24/12/1999 | 16/6/2026 | Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font. | |
| Modificada | Media (5) | 1.4% | — | Netscape Communicator | 22/12/1999 | 16/6/2026 | Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords." | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Netscape Enterprise ServerNovell Groupwise | 19/12/1999 | 16/6/2026 | Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter. | |
| Modificada | Alta (10) | 3.4% | — | Netscape Enterprise ServerNetscape Fasttrack Server | 1/12/1999 | 16/6/2026 | Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure. | |
| Modificada | Alta (7.5) | 2.5% | — | Netscape CommunicatorNetscape Navigator | 24/11/1999 | 16/6/2026 | Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. | |
| Modificada | Baja (2.6) | 4.8% | — | Microsoft IEMicrosoft Internet ExplorerNetscape Navigator | 1/11/1999 | 16/6/2026 | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. |