Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.1% | — | HP PKI Activex Control | 12/1/2013 | 16/6/2026 | The KillProcess method in the HP PKI ActiveX control (HPPKI.ocx) before 1.2.0.1 allows remote attackers to cause a denial of service (kill process) via the partial or full name of a process. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Dlink Camera Stream Client Activex ControlDlink Dcs-5605 PTZ IP Network Camera | 6/10/2012 | 16/6/2026 | Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as used in D-Link DCS-5605 PTZ IP Network Camera, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string argument. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Dart Powertcp Activex | 4/10/2012 | 16/6/2026 | Stack consumption vulnerability in dartwebserver.dll 1.9 and earlier, as used in Dart PowerTCP WebServer for ActiveX and other products, allows remote attackers to cause a denial of service (daemon crash) via a long request. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Asus Ipswcom Activex ComponentAsus Net4switch | 15/9/2012 | 16/6/2026 | Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method. | |
| Modificada | Alta (9.3) | 9.8% | 💥 Exploit | Oracle Hyperion Strategic FinanceTidestone Formula ONE Activex Control | 15/9/2012 | 16/6/2026 | Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter. | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Trendnet Securview Wireless Internet Camera Activex ControlTrendnet Securview Wireless Internet Camera | 6/9/2012 | 16/6/2026 | Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Cisco Linksys Playerpt Activex Control | 19/7/2012 | 16/6/2026 | Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument). | |
| Modificada | Alta (9.3) | 5.1% | — | Luratech Lurawave JP2 Activex Control | 2/2/2012 | 16/6/2026 | Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | |
| Modificada | Alta (9.3) | 39% | 💥 Exploit | Ntrglobal NTR Activex Control | 15/1/2012 | 16/6/2026 | The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a crafted lModule parameter that triggers use of an arbitrary memory address as a function pointer. | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Ntrglobal NTR Activex Control | 15/1/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitrary code via (1) a long bstrUrl parameter to the StartModule method, (2) a long bstrParams parameter to the Check method, a long bstrUrl parameter to the (3) Download or (4) DownloadModule method… | |
| Modificada | Alta (9.3) | 2.9% | — | Sunplus-tech DVR Remote Activex Control | 26/11/2011 | 16/6/2026 | DVRemoteAx.ax 2.1.0.39 in the DVR Remote ActiveX control allows remote attackers to execute arbitrary code via a crafted DVRobot.dll file in a manifest directory on a web server. | |
| Modificada | Alta (9.3) | 1.9% | — | Uusee Uuplayer Activex ControlUusee | 9/8/2011 | 16/6/2026 | The Play method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 allows remote attackers to execute arbitrary programs via a UNC share pathname in the MPlayerPath parameter. | |
| Modificada | Alta (9.3) | 4.2% | — | Uusee Uuplayer Activex ControlUusee | 9/8/2011 | 16/6/2026 | Heap-based buffer overflow in the SendLogAction method in the UUPlayer ActiveX control 6.0.0.1 in UUSee 2010 6.11.0609.2 might allow remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (9.3) | 5.4% | — | Provideo Alarm Activex ControlProvideo Gmax Activex ControlProvideo Paxplayer Activex Control | 5/8/2011 | 16/6/2026 | Multiple buffer overflows in the Provideo ActiveX controls allow remote attackers to execute arbitrary code via crafted input fields, as demonstrated by (1) a long strIp argument to the voice method in 2way.dll in the alarm 1.0.3.1 ActiveX control, (2) a network response to AXPlayer.ocx in the GMAXPlayer 2.0.8.2… | |
| Modificada | Alta (9.3) | 4.5% | — | Honeywell Scanserver Activex Control | 22/3/2011 | 16/6/2026 | Use-after-free vulnerability in the addOSPLext method in the Honeywell ScanServer ActiveX control 780.0.20.5 allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Media (5) | 1.2% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest property, which allows remote attackers to execute arbitrary WMI Query Language (WQL) statements via a crafted value, as demonstrated by a value that triggers disclosure of… | |
| Modificada | Media (5) | 1.6% | — | Dellsystemlite.scanner Activex Control | 21/2/2011 | 16/6/2026 | Directory traversal vulnerability in the GetData method in the Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 allows remote attackers to read arbitrary files via directory traversal sequences in the fileID parameter. | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Moxa Activex SDK | 18/2/2011 | 16/6/2026 | Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows remote attackers to execute arbitrary code via a long PlayFileName property value. | |
| Modificada | Alta (9.3) | 5.5% | — | Topazsystems Sigplus PRO Activex Control | 7/2/2011 | 16/6/2026 | Multiple heap-based buffer overflows in Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allow remote attackers to execute arbitrary code via a long (1) KeyString property, (2) NewPath parameter to the SetLocalIniFilePath method, or (3) NewPortPath parameter to the… | |
| Modificada | Alta (9.3) | 4.8% | — | Topazsystems Sigplus PRO Activex Control | 7/2/2011 | 16/6/2026 | Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary content. | |
| Modificada | Media (6.8) | 1.0% | — | Redhat Spice-activexRedhat Enterprise Virtualization Manager | 8/12/2010 | 16/6/2026 | Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of… | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. | |
| Modificada | Alta (10) | 4.9% | — | Realpage Module Activex Control | 26/10/2010 | 16/6/2026 | Multiple buffer overflows in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls allow remote attackers to execute arbitrary code via a long (1) DestURL or (2) SourceFile property value. | |
| Modificada | Media (5) | 1.4% | — | Realpage Module Activex Controls | 26/10/2010 | 16/6/2026 | The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL… | |
| Modificada | Alta (9.3) | 3.9% | — | Oracle Siebel Option Pack IE Activex Control | 17/8/2010 | 16/6/2026 | The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document. |