Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.3) | 0.60% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered. | |
| Modificada | Media (4.3) | 1.9% | — | RIM Blackberry SoftwareRIM Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 with 4.0 SP1 Bundle 83 allows remote attackers to cause a denial of service (blocked call reception) via a malformed SIP invite message, possibly related to multiple format string specifiers in the From field, a spoofed source IP address, and limitations of the function stack… | |
| Modificada | Baja (2.3) | 0.67% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header. | |
| Modificada | Baja (3.5) | 0.92% | — | Plain Black Webgui | 17/5/2007 | 16/6/2026 | The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact. | |
| Modificada | Media (5) | 7.8% | 💥 Exploit | Blackdot Imageview | 2/5/2007 | 16/6/2026 | Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the album parameter. | |
| Modificada | Media (4.3) | 1.7% | — | RIM Blackberry 8100RIM BlackberryRIM Blackberry Browser | 14/3/2007 | 16/6/2026 | The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page. | |
| Modificada | Baja (2.1) | 0.78% | 💥 Exploit | ISS Blackice PC Protection | 6/3/2007 | 16/6/2026 | ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection scheme by using the ZwDeleteFile API function to delete the critical filelock.txt file, which stores information about protected files. | |
| Modificada | Media (6.4) | 1.4% | — | Plain Black Webgui | 31/1/2007 | 16/6/2026 | The www_purgeList method in Plain Black WebGUI before 7.3.8 does not properly check user permissions, which allows attackers to delete unauthorized assets. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.4% | — | Plain Black Webgui | 23/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Operation/User.pm in Plain Black WebGUI before 7.3.5 (beta) allows remote attackers to inject arbitrary web script or HTML via the username parameter during anonymous registration, a different vector than CVE-2007-0308. NOTE: it is possible that a separate "WikiPage titles"… | |
| Modificada | Media (6.8) | 1.2% | — | Plain Black Webgui | 18/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.3.4 (beta) allows remote attackers to inject arbitrary web script or HTML via Wiki Page titles. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Blackdot Imageview | 26/10/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/plain .gif file containing PHP code, which is executed by… | |
| Modificada | Media (5) | 1.5% | — | RIM Blackberry Enterprise Server | 25/10/2006 | 16/6/2026 | Research in Motion (RIM) BlackBerry Enterprise Server 4.1 SP2 before Hotfix 1 for IBM Lotus Domino might allow attackers with meeting organizer privileges to cause a denial of service (application hang) via a deleted recurrent meeting instance when changing the attendee's calendar meeting time. | |
| Modificada | Media (4.6) | 0.73% | 💥 Exploit | ISS Blackice PC Protection | 5/9/2006 | 16/6/2026 | RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | BlackboardBlackboard Learning AND Community Portal SuiteBlackboard Vista | 23/8/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community Portal Suite 6.2.3.23, and Blackboard Vista 4 allow remote attackers to inject arbitrary Javascript, VBScript, or HTML via (1) data, (2) vbscript, and (3) malformed javascript URIs in various HTML… | |
| Modificada | Media (4.6) | 0.33% | — | ISS Blackice PC Protection | 5/8/2006 | 16/6/2026 | ISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE library, which allows local users to subvert BlackICE by replacing pamversion.dll. NOTE: in most cases, the attack would not cross privilege boundaries because replacing… | |
| Modificada | Media (6) | 1.1% | — | Blackboard Academic Suite | 28/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Blackboard Academic Suite 6.2.3.23 allows remote authenticated users to inject arbitrary HTML or web script by bypassing client-side validation through disabling JavaScript when submitting an essay response, which has no server-side validation before being viewed via "View… | |
| Modificada | Media (5) | 2.4% | — | ISS Blackice PC ProtectionISS Blackice Server ProtectionISS Proventia DesktopISS Realsecure Desktop+6 | 27/7/2006 | 16/6/2026 | The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is… | |
| Modificada | Alta (7.5) | 1.5% | 💥 Exploit | Blackorpheus Clanmemberskript | 20/4/2006 | 16/6/2026 | SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter. | |
| Modificada | Media (5.1) | 2.7% | — | RIM Blackberry Enterprise Server | 18/2/2006 | 16/6/2026 | Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers… | |
| Modificada | Media (5) | 1.4% | — | Plain Black Webgui | 15/2/2006 | 16/6/2026 | Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous registration is disabled, via a certain URL. | |
| Modificada | Media (4.3) | 0.36% | — | BlackboardBlackboard Academic Suite | 1/2/2006 | 16/6/2026 | Blackboard Academic Suite 6.0 and earlier does not properly clear session information when de-authenticating a user who is idle, which allows subsequent users to log in as the previous user and gain privileges. NOTE: the vendor has disputed this issue, saying that "This is a customer specific issue related to their… | |
| Modificada | Media (4.3) | 1.2% | — | Plain Black Webgui | 11/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the DataForm Entries functionality in Plain Black WebGUI before 6.8.4 (gamma) allows remote attackers to inject arbitrary Javascript via the (1) url and (2) name field of the default email form. | |
| Modificada | Media (5) | 2.5% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 2.2% | — | RIM Blackberry Attachment ServiceRIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file. | |
| Modificada | Alta (7.5) | 3.2% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbitrary code via certain data packets. |