Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.9% | — | Yahoo Toolbar | 27/12/2007 | 16/6/2026 | Buffer overflow in the YShortcut ActiveX control in YShortcut.dll 2006.8.15.1 in Yahoo! Toolbar might allow attackers to execute arbitrary code via a long string to the IsTaggedBM method. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Yahoo Toolbar | 4/12/2007 | 16/6/2026 | Stack-based buffer overflow in the Helper class in the yt.ythelper.2 ActiveX control in Yahoo! Toolbar 1.4.1 allows remote attackers to cause a denial of service (browser crash) via a long argument to the c method. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Ask.com ASK Toolbar | 26/9/2007 | 16/6/2026 | Stack-based buffer overflow in the AskJeevesToolBar.SettingsPlugin.1 ActiveX control in askBar.dll in IAC Search & Media ask.com Ask Toolbar 4.0.2.53 and earlier allows remote attackers to execute arbitrary code via a long ShortFormat property value. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (10) | 2.5% | 💥 Exploit | Ask.com ASK Toolbar | 26/9/2007 | 16/6/2026 | Unspecified vulnerability in IAC Search & Media ask.com toolbar has unknown impact and remote attack vectors. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not coordinate with vendors or release actionable advisories. A CVE has been assigned for… | |
| Modificada | Media (4.3) | 1.2% | — | Exportnation Toolbar | 8/8/2007 | 16/6/2026 | The isChecked function in Toolbar.DLL in the ExportNation toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. | |
| Modificada | Media (4.3) | 1.2% | — | Toolbar Gaming | 8/8/2007 | 16/6/2026 | The CallCmd function in toolbar_gaming.dll in the Toolbar Gaming toolbar for Internet Explorer allows remote attackers to cause a denial of service (NULL dereference and browser crash) via unspecified vectors. | |
| Modificada | Media (6.8) | 8.2% | 💥 Exploit | Linkedin Toolbar | 24/7/2007 | 16/6/2026 | Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.1098 allows remote attackers to execute arbitrary code via a long second argument (varBrowser argument) to the search method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Netsprint Toolbar | 15/5/2007 | 16/6/2026 | Buffer overflow in the isChecked function in toolbar.dll in Netsprint Toolbar 1.1 might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.1) | 1.1% | — | Brujula Toolbar | 11/5/2007 | 16/6/2026 | Unspecified vulnerability in the GetPropertyById function in ISoftomateObj in SoftomateLib in BRUJULA4.NET.DLL in the Brujula Toolbar (Brujula.net toolbar) allows attackers to cause a denial of service (NULL dereference and browser crash) via certain arguments. | |
| Modificada | Alta (7.8) | 3.4% | 💥 Exploit | Netsprint ASK IE Toolbar | 24/4/2007 | 16/6/2026 | A certain ActiveX control in askPopStp.dll in Netsprint Ask IE Toolbar 1.1 allows remote attackers to cause a denial of service (Internet Explorer crash) via a long AddAllowed property value, related to "improper memory handling," possibly a buffer overflow. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Rediff Toolbar | 10/3/2007 | 16/6/2026 | The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via unspecified manipulations, possibly involving improper initialization or blank arguments. | |
| Modificada | Baja (2.6) | 1.3% | — | ICQ INC ICQ Toolbar | 9/9/2006 | 16/6/2026 | AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) does not properly validate the origin of the configuration web page (options2.html), which allows user-assisted remote attackers to provide a web page that contains disguised checkboxes that trick the user into reconfiguring the toolbar. | |
| Modificada | Media (5.8) | 1.3% | — | ICQ INC ICQ Toolbar | 9/9/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the RSS Feed module in AOL ICQ Toolbar 1.3 for Internet Explorer (toolbaru.dll) allow remote attackers to process arbitrary web script or HTML in the Feeds interface context via the (1) title and (2) description elements within an item element in an RSS feed. | |
| Modificada | Alta (7.5) | 3.2% | — | Athoc Toolbar | 2/5/2005 | 16/6/2026 | Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name. | |
| Modificada | Media (4.3) | 3.2% | 💥 Exploit | Google Toolbar | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Google Toolbar 2.0.114.1 allows remote attackers to inject arbitrary web script via about.html in the About section. NOTE: some followup posts suggest that the demonstration code's use of the res:// protocol does not cross privilege boundaries, since it is not allowed in the… | |
| Modificada | Alta (7.5) | 2.7% | — | Athoc Toolbar | 6/10/2004 | 16/6/2026 | Format string vulnerability in the SetBaseURL function in AtHoc toolbar allows remote attackers to execute arbitrary code via format string specifiers in an invalid URL that is recorded in the debug log. | |
| Modificada | Alta (7.5) | 1.4% | — | Google Toolbar | 11/4/2003 | 16/6/2026 | The Google toolbar 1.1.58 and earlier allows remote web sites to perform unauthorized toolbar operations including script execution and file reading in other zones such as "My Computer" by opening a window to tools.google.com or the res: protocol, then using script to modify the window's location to the toolbar's… | |
| Modificada | Media (5) | 1.3% | — | Google Toolbar | 11/4/2003 | 16/6/2026 | The Google toolbar 1.1.58 and earlier allows remote web sites to monitor a user's input into the toolbar via an "onkeydown" event handler. | |
| Modificada | Baja (2.1) | 0.35% | — | Commonname Toolbar | 31/12/2002 | 16/6/2026 | CommonName Toolbar 3.5.2.0 sends unqualified domain name requests to the CommonName organization and possibly other web servers for name resolution, which allows those organizations to obtain internal server names. | |
| Modificada | Baja (2.6) | 14% | 💥 Exploit | Google ToolbarMicrosoft Internet Explorer | 15/8/2002 | 16/6/2026 | The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function. |