Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 4.9% | — | Realpage Module Activex Control | 26/10/2010 | 16/6/2026 | Multiple buffer overflows in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls allow remote attackers to execute arbitrary code via a long (1) DestURL or (2) SourceFile property value. | |
| Modificada | Media (5) | 1.4% | — | Realpage Module Activex Controls | 26/10/2010 | 16/6/2026 | The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL… | |
| Modificada | Alta (9.3) | 3.9% | — | Oracle Siebel Option Pack IE Activex Control | 17/8/2010 | 16/6/2026 | The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document. | |
| Modificada | Alta (9.3) | 4.5% | — | Invensys Wonderware Archestra Configuration Access Component Activex ControlInvensys Wonderware Application Server | 5/8/2010 | 16/6/2026 | Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated… | |
| Modificada | Alta (9.3) | 6.9% | 💥 Exploit | Barcodewiz Barcode Activex Control | 5/8/2010 | 16/6/2026 | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method. | |
| Modificada | Alta (9.3) | 9.4% | 💥 Exploit | Topazsystems Sigplus PRO Activex Control | 5/8/2010 | 16/6/2026 | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method. | |
| Modificada | Alta (10) | 3.2% | — | Gigabyte Dldrv2 Activex Control | 2/8/2010 | 16/6/2026 | Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via the item argument. | |
| Modificada | Alta (10) | 1.8% | — | Gigabyte Dldrv2 Activex Control | 2/8/2010 | 16/6/2026 | The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the… | |
| Modificada | Alta (10) | 4.6% | — | Creative Autoupdate Engine Activex ControlCreative Autoupdate | 15/6/2010 | 16/6/2026 | Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method. | |
| Modificada | Alta (9.3) | 4.8% | — | Larts Uploader Activex Control | 3/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value. | |
| Modificada | Alta (8.8) | 8.9% | 💥 Exploit | AOL Superbuddy Activex Control | 9/10/2009 | 16/6/2026 | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method. | |
| Modificada | Alta (9.3) | 4.8% | 💥 Exploit | Chilkatsoft Chilkat Imap Activex Control | 21/8/2009 | 16/6/2026 | Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method. | |
| Modificada | Alta (9.3) | 4.1% | — | Ebay Enhanced Picture Uploader Activex Control | 9/6/2009 | 16/6/2026 | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property. | |
| Modificada | Alta (9.3) | 5.6% | — | Dlink Mpeg4 Viewer Activex Control | 20/5/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (8.8) | 1.7% | — | Versalsoft Http File Upload Activex Control | 7/4/2009 | 16/6/2026 | Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method. | |
| Modificada | Alta (7.8) | 5.7% | 💥 Exploit | Precisionid Data Matrix Barcode Activex Control | 1/4/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods. | |
| Modificada | Alta (9.3) | 8.8% | 💥 Exploit | Geovision Liveaudio Activex Control | 25/3/2009 | 16/6/2026 | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | IBM Access Support Activex Control | 25/3/2009 | 16/6/2026 | Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 5.5% | 💥 Exploit | Geovision Livex Activex Control | 10/3/2009 | 16/6/2026 | Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods. | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | Sopcast Sopcore Activex Control | 4/3/2009 | 16/6/2026 | Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method. | |
| Modificada | Alta (9.3) | 16% | — | SapguiSimba Technologies Mdrmsap Activex Control | 10/11/2008 | 16/6/2026 | Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Chilkat Software Chilkat Crypt Activex Control | 10/11/2008 | 16/6/2026 | Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in… | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Djvu Activex Control FOR Microsoft Office 2000 | 4/11/2008 | 16/6/2026 | Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties. | |
| Modificada | Alta (9.3) | 8.7% | 💥 Exploit | Chilkat Software Chilkat XML Activex Control | 30/9/2008 | 16/6/2026 | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited… | |
| Modificada | Alta (9.3) | 7.7% | — | Nctsoft Nctaudioeditor Activex Control | 29/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors. |