Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
352 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Stalker Communigate PRO | 30/1/2006 | 16/6/2026 | CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite. | |
| Modificada | Media (5.4) | 0.82% | — | Google Talk | 29/11/2005 | 16/6/2026 | The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory during the signature verification, aka BenjiBug. | |
| Modificada | Media (5) | 0.83% | — | Google Talk | 18/11/2005 | 16/6/2026 | Google Talk before 1.0.0.76, with email notification enabled, allows remote attackers to cause a denial of service (connection reset) via email with a blank sender. | |
| Modificada | Media (4.3) | 1.3% | — | N-stalker N-stealth | 8/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report. | |
| Modificada | Media (5) | 2.5% | — | Stalker Communigate PRO | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages. | |
| Modificada | Baja (2.1) | 0.39% | — | Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core | 9/2/2005 | 16/6/2026 | The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Media (6.5) | 1.8% | 💥 Exploit | Fusetalk | 31/12/2004 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FuseTalk 2.0 allows remote attackers to create arbitrary accounts via a link to adduser.cfm. | |
| Modificada | Media (4.3) | 1.3% | — | E-zone Media Inc. Fusetalk | 13/10/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 4.0 allows remote attackers to execute arbitrary web script via an img src tag. | |
| Modificada | Media (6.4) | 4.1% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path"). | |
| Modificada | Alta (10) | 10% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the… | |
| Modificada | Media (5) | 1.6% | — | E-zone Media Inc. Fusetalk | 5/5/2004 | 16/6/2026 | FuseTalk 4.0 allows remote attackers to ban other users via a direct request to banning.cfm. | |
| Modificada | Alta (7.2) | 0.40% | — | Xintercepttalk Xitalk | 15/4/2004 | 16/6/2026 | Unknown vulnerability in xitalk 1.1.11 and earlier allows local users to execute arbitrary commands. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Stalker Communigate PRO | 31/12/2003 | 16/6/2026 | CommuniGate Pro 3.1 through 4.0.6 sends the session ID in the referer field for an HTTP request for an image, which allows remote attackers to hijack mail sessions via an e-mail with an IMG tag that references a malicious URL that captures the referer. | |
| Modificada | Alta (7.5) | 9.1% | 💥 Exploit | Microsoft Biztalk Server | 12/5/2003 | 16/6/2026 | Buffer overflow in the HTTP receiver function (BizTalkHTTPReceive.dll ISAPI) of Microsoft BizTalk Server 2002 allows attackers to execute arbitrary code via a certain request to the HTTP receiver. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Microsoft Biztalk Server | 12/5/2003 | 16/6/2026 | SQL injection vulnerability in the Document Tracking and Administration (DTA) website of Microsoft BizTalk Server 2000 and 2002 allows remote attackers to execute operating system commands via a request to (1) rawdocdata.asp or (2) RawCustomSearchField.asp containing an embedded SQL statement. | |
| Modificada | Alta (7.8) | 2.0% | — | Calisto Internet Talker | 31/12/2002 | 16/6/2026 | Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow. | |
| Modificada | Media (4.3) | 0.94% | — | E-zone Media Inc. Fusetalk | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FuseTalk 2.0 and 3.0 allows remote attackers to insert arbitrary HTML and web script. | |
| Modificada | Media (5) | 1.5% | — | Stalker Communigate PRO | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. NOTE: it is not clear whether this issue reveals any more information regarding… | |
| Modificada | Media (4.6) | 0.33% | — | E-zone Media Fuse Talk | 6/12/2001 | 16/6/2026 | join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable. | |
| Modificada | Alta (10) | 5.7% | — | Tooltalk Database Server | 30/10/2001 | 16/6/2026 | Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function. | |
| Modificada | Media (5) | 3.4% | — | WAY TO THE WEB Talkback | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Stalker Communigate PRO | 11/12/2000 | 23/9/2026 | POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to determine valid email addresses on the server for SPAM attacks. | |
| Modificada | Baja (2.6) | 1.3% | — | Stalkerlab Mailers | 20/10/2000 | 16/6/2026 | CGIMail.exe CGI program in Stalkerlab Mailers 1.1.2 allows remote attackers to read arbitrary files by specifying the file in the $Attach$ hidden form variable. | |
| Modificada | Media (5) | 7.9% | 💥 Exploit | Stalker Communigate PRO | 3/4/2000 | 16/6/2026 | The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.5% | — | Stalker Communigate PRO | 3/12/1999 | 16/6/2026 | Buffer overflow in CommuniGatePro via a long string to the HTTP configuration port. |