Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.49%—Netscape Iplanet Ical11/12/200016/6/2026
csstart program in iCal 2.1 Patch 2 searches for the cshttpd program in the current working directory, which allows local users to gain root privileges by creating a Trojan Horse cshttpd program in a directory and calling csstart from that directory.
ModificadaMedia (5)6.0%💥 ExploitNetscape Directory ServerSUN Iplanet Certificate Management System11/12/200016/6/2026
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the Agent, End Entity, or Administrator services.
ModificadaAlta (10)3.0%—Netscape Iplanet Ical11/12/200016/6/2026
The GUI installation for iCal 2.1 Patch 2 disables access control for the X server using an "xhost +" command, which allows remote attackers to monitor X Windows events and gain privileges.
ModificadaAlta (10)4.1%💥 ExploitNetscape Iplanet Ical11/12/200023/9/2026
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could allow the icsuser account to gain root privileges by creating a Trojan Horse library in the current or parent directory.
ModificadaAlta (7.5)34%💥 ExploitMicrosoft Virtual MachineNetscape Communicator20/10/200016/6/2026
Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice.
ModificadaMedia (5)20%💥 ExploitNetscape Communicator20/10/200016/6/2026
Netscape Communicator and Navigator 4.04 through 4.74 allows remote attackers to read arbitrary files by using a Java applet to open a connection to a URL using the "file", "http", "https", and "ftp" protocols, as demonstrated by Brown Orifice.
ModificadaMedia (5)13%💥 ExploitMozillaNetscape Communicator25/7/200016/6/2026
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary commands via a JPEG image containing a comment with an illegal field length of 1.
ModificadaAlta (7.5)2.4%—Netscape Enterprise ServerNovell Netware26/6/200016/6/2026
Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed URL.
ModificadaAlta (10)4.5%💥 ExploitNetscape Professional Services Ftpserver21/6/200016/6/2026
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)1.3%—Netscape Communicator26/5/200016/6/2026
Netscape 4.73 and earlier does not properly warn users about a potentially invalid certificate if the user has previously accepted the certificate for a different web site, which could allow remote attackers to spoof a legitimate web site by compromising that site's DNS information.
ModificadaBaja (2.6)1.0%—Netscape Communicator10/5/200016/6/2026
Netscape Communicator before version 4.73 and Navigator 4.07 do not properly validate SSL certificates, which allows remote attackers to steal information by redirecting traffic from a legitimate web server to their own malicious server, aka the "Acros-Suencksen SSL" vulnerability.
ModificadaBaja (3.7)0.31%💥 ExploitNetscape Communicator10/5/200016/6/2026
Netscape 4.73 and earlier follows symlinks when it imports a new certificate, which allows local users to overwrite files of the user importing the certificate.
ModificadaBaja (2.6)1.0%—Netscape Communicator1/4/200016/6/2026
A remote attacker can read information from a Netscape user's cache via JavaScript.
ModificadaMedia (5)5.9%💥 ExploitNetscape Enterprise Server17/3/200016/6/2026
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing tags such as ?wp-ver-info and ?wp-cs-dump.
ModificadaMedia (6.4)2.1%—Netscape Enterprise Server11/3/200016/6/2026
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for the /publisher directory, which provides a Java applet that allows the attacker to browse the directories.
ModificadaMedia (5)0.78%—Netscape Communicator12/1/200016/6/2026
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.
ModificadaMedia (5)1.3%—Netscape CommunicatorNetscape Navigator12/1/200016/6/2026
Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext.
ModificadaMedia (5)0.88%—Globalscape Cuteftp6/1/200016/6/2026
CuteFTP uses weak encryption to store password information in its tree.dat file.
ModificadaAlta (7.5)2.5%💥 ExploitNetscape Enterprise ServerNetscape Fasttrack Server4/1/200016/6/2026
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET request.
ModificadaMedia (4.6)0.40%—Netscape Communicator24/12/199916/6/2026
Buffer overflow in Netscape Communicator before 4.7 via a dynamic font whose length field is less than the size of the font.
ModificadaMedia (5)1.4%—Netscape Communicator22/12/199916/6/2026
Netscape 4.7 records user passwords in the preferences.js file during an IMAP or POP session, even if the user has not enabled "remember passwords."
ModificadaMedia (5)7.9%💥 ExploitNetscape Enterprise ServerNovell Groupwise19/12/199916/6/2026
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack using the HELP parameter.
ModificadaAlta (10)3.4%—Netscape Enterprise ServerNetscape Fasttrack Server1/12/199916/6/2026
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.
ModificadaAlta (7.5)2.5%—Netscape CommunicatorNetscape Navigator24/11/199916/6/2026
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.
ModificadaBaja (2.6)4.8%—Microsoft IEMicrosoft Internet ExplorerNetscape Navigator1/11/199916/6/2026
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.
Orbitaley — Vulnerabilidades