Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.0% | — | Evolution-extreme Nuke Evolution Xtreme | 28/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.1% | — | Fullrevolution Aspwebcalendar | 2/4/2009 | 16/6/2026 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb. | |
| Modificada | Alta (7.5) | 3.3% | — | Go-evolution Evolution-data-server | 14/3/2009 | 16/6/2026 | Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel. | |
| Modificada | Media (5.8) | 2.3% | — | Gnome Evolution-data-server | 14/3/2009 | 16/6/2026 | The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a… | |
| Modificada | Media (5) | 2.2% | — | Evolution | 12/2/2009 | 16/6/2026 | Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077. | |
| Modificada | Alta (10) | 12% | — | Fullrevolution Aspwebcalendar2008 | 24/6/2008 | 16/6/2026 | Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attackers to upload and execute arbitrary code via the FILE1 parameter in an uploadfileprocess action, probably followed by a direct request to the file in calendar/eventimages/. | |
| Modificada | Alta (7.6) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment. | |
| Modificada | Alta (9.3) | 5.7% | — | Gnome Evolution | 4/6/2008 | 16/6/2026 | Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window). | |
| Modificada | Media (6.8) | 6.0% | — | Gnome Evolution | 6/3/2008 | 16/6/2026 | Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field. | |
| Modificada | Alta (7.8) | 2.3% | — | Tumusika Evolution | 4/12/2007 | 16/6/2026 | TuMusika Evolution 1.7R5 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 4.0% | — | Tumusika Evolution | 30/11/2007 | 16/6/2026 | Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) languages_n.php, (2) languages_f.php, or (3) languages.php in inc/; and (4) allow remote attackers to read arbitrary local… | |
| Modificada | Media (4.3) | 2.3% | — | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in session.cgi (aka the login page) in Google Urchin 5 5.7.03 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, a different vulnerability than CVE-2007-4713. NOTE: this can be leveraged to capture login credentials in some browsers… | |
| Modificada | Media (5) | 3.0% | — | ROI Revolution Urchin | 26/9/2007 | 16/6/2026 | report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112. | |
| Modificada | Alta (7.5) | 3.7% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Format string vulnerability in CellFactor Revolution 1.03 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a malformed nickname. | |
| Modificada | Alta (7.5) | 6.1% | — | Immersion Games Cellfactor Revolution | 12/9/2007 | 16/6/2026 | Multiple buffer overflows in CellFactor Revolution 1.03 and earlier allow remote attackers to execute arbitrary code via a long string in a (1) 0x21, (2) 0x22, or (3) 0x23 packet. | |
| Modificada | Media (4.3) | 1.2% | — | ROI Revolution Urchin | 5/9/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in urchin.cgi in Urchin 5.6.00r2 allow remote attackers to inject arbitrary web script or HTML via the (1) dtc, (2) vid, (3) n, (4) dt, (5) ed, and (6) bd parameters. | |
| Modificada | Media (6.8) | 3.1% | — | Gnome Evolution | 19/6/2007 | 16/6/2026 | Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index. | |
| Modificada | Alta (7.5) | 1.5% | — | B2evolution | 15/5/2007 | 16/6/2026 | Directory traversal vulnerability in blogs/index.php in b2evolution 1.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the core_subdir parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | B2evolution | 30/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in b2evolution allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_path parameter to (a) a_noskin.php, (b) a_stub.php, (c) admin.php, (d) contact.php, (e) default.php, (f) index.php, and (g) multiblogs.php in blogs/; the (2) view_path and (3)… | |
| Modificada | Alta (7.5) | 4.1% | — | Post Revolution | 24/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Post Revolution 6.6 and 7.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the dir parameter to (1) common.php or (2) themes/default/preview_post_completo.php. | |
| Modificada | Media (6.8) | 1.7% | — | Tumusika Evolution | 18/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TuMusika Evolution 1.6 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Revolutionproducts Flexbb | 28/3/2007 | 16/6/2026 | SQL injection vulnerability in includes/start.php in Flexbb 1.0.0 10005 Beta Release 1 allows remote attackers to execute arbitrary SQL commands via the flexbb_lang_id COOKIE parameter to index.php. | |
| Modificada | Media (6.8) | 3.4% | — | Evolution Shared Memo | 21/3/2007 | 16/6/2026 | Format string vulnerability in the write_html function in calendar/gui/e-cal-component-memo-preview.c in Evolution Shared Memo 2.8.2.1, and possibly earlier versions, allows user-assisted remote attackers to execute arbitrary code via format specifiers in the categories of a crafted shared memo. | |
| Modificada | Media (5) | 5.2% | — | Gnome Evolution | 6/3/2007 | 16/6/2026 | Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution from visually distinguishing between signed and unsigned portions of OpenPGP messages with multiple components, which allows remote attackers to forge the contents of a message without detection. | |
| Modificada | Media (4.3) | 1.3% | — | B2evolution | 11/1/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in htsrv/login.php in b2evolution 1.8.6 allows remote attackers to inject arbitrary web script or HTML via scriptable attributes in the redirect_to parameter. |