Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.2% | 💥 Exploit | Idevspot Phplinkexchange | 13/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the svr_rootPhpStart parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Idevspot Phplinkexchange | 24/7/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Alta (10) | 4.1% | — | Oracle Exchange | 21/7/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Oracle Exchange for Oracle E-Business Suite and Applications 6.2.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS16 and (2) APPS17. | |
| Analizada | Media (4.3) | 1.8% | 💥 Exploit | Softbizscripts Banner Exchange Script | 18/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php,… | |
| Modificada | Media (5) | 1.9% | — | Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp | 24/6/2006 | 16/6/2026 | Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to cause a denial of service via (1) non-ASCII characters in a reverse DNS lookup result from a Received header, which leads to a Receiver service stop, and (2) unspecified vectors involving malformed… | |
| Modificada | Alta (7.5) | 1.7% | — | Clearswift Mailsweeper FOR ExchangeClearswift Mailsweeper FOR Smtp | 24/6/2006 | 16/6/2026 | Clearswift MAILsweeper for SMTP before 4.3.20 and MAILsweeper for Exchange before 4.3.20 allows remote attackers to bypass the "text analysis", possibly bypassing SPAM and other filters, by sending an e-mail specifying a non-existent or unrecognized character set. | |
| Modificada | Media (5.1) | 2.1% | — | Eschew.net Phpbannerexchange | 19/6/2006 | 16/6/2026 | Interpretation conflict in resetpw.php in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via an email parameter containing a null (%00) character after a valid e-mail address, which passes the validation check in the eregi PHP command. NOTE: it could be argued that this… | |
| Modificada | Alta (7.5) | 1.5% | — | Eschew.net Phpbannerexchange | 19/6/2006 | 16/6/2026 | SQL injection vulnerability in phpBannerExchange before 2.0 Update 6 allows remote attackers to execute arbitrary SQL commands via the (1) login parameter in (a) client/stats.php and (b) admin/stats.php, or the (2) pass parameter in client/stats.php. | |
| Modificada | Baja (2.6) | 40% | 💥 Exploit | Microsoft Exchange Server | 13/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing." | |
| Modificada | Media (5) | 2.8% | — | Internet KEY Exchange | 10/5/2006 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. | |
| Modificada | Alta (7.5) | 79% | — | Microsoft Exchange Server | 10/5/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties. | |
| Modificada | Media (5) | 2.4% | — | Internet KEY Exchange | 6/4/2006 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to… | |
| Modificada | Media (5) | 2.8% | — | Eschew.net Phpbannerexchange | 14/3/2006 | 16/6/2026 | Directory traversal vulnerability in resetpw.php in eschew.net phpBannerExchange 2.0 and earlier, and other versions before 2.0 Update 5, allows remote attackers to read arbitrary files via a .. (dot dot) in the email parameter during a "Recover password" operation (recoverpw.php). | |
| Modificada | Alta (7.5) | 42% | 💥 Exploit | Kinesphere Corporation Exchange Pop3 | 4/2/2006 | 16/6/2026 | Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument. | |
| Modificada | Alta (7.5) | 46% | — | Microsoft Exchange ServerMicrosoft OfficeMicrosoft Outlook | 10/1/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation. | |
| Modificada | Media (6.4) | 1.2% | — | Suse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard ServerSuse Sled Beagle+1 | 31/12/2005 | 16/6/2026 | liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Alta (7.5) | 5.6% | — | Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+15 | 30/11/2005 | 16/6/2026 | Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive. | |
| Modificada | Media (5) | 2.4% | — | Internet KEY Exchange | 18/11/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original… | |
| Modificada | Media (5) | 2.9% | — | Internet KEY Exchange | 18/11/2005 | 16/6/2026 | Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is… | |
| Modificada | Alta (10) | 3.4% | — | Internet KEY Exchange | 18/11/2005 | 16/6/2026 | Multiple unspecified format string vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is… | |
| Modificada | Alta (7.5) | 44% | — | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows Server 2003Microsoft Windows XP | 13/10/2005 | 16/6/2026 | Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string. | |
| Modificada | Media (4.3) | 14% | — | Microsoft Exchange Server | 14/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc
ript:") in an IMG tag. | |
| Modificada | Alta (7.5) | 69% | 💥 Exploit | Microsoft Exchange Server | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port. | |
| Modificada | Alta (7.5) | 33% | — | Microsoft Exchange ServerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+3 | 2/5/2005 | 16/6/2026 | The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability." |