Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer,… | |
| Modificada | Alta (8.1) | 22% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel… | |
| Modificada | Alta (9.3) | 24% | — | Microsoft Windows 2003 ServerMicrosoft Windows Server 2008Microsoft Windows VistaMicrosoft Windows XP+22 | 14/10/2009 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office… | |
| Modificada | Alta (7.6) | 5.5% | — | Cisco Unified Communications Manager ExpressCisco IOS | 28/9/2009 | 16/6/2026 | Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779. | |
| Modificada | Baja (3.5) | 1.0% | — | Cisco CRSCisco Customer Response ApplicationsCisco IP QMCisco Unified CCX+2 | 16/7/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors. | |
| Modificada | Alta (9) | 2.4% | — | Cisco CRSCisco Customer Response ApplicationsCisco IP QMCisco Unified CCX+2 | 16/7/2009 | 16/6/2026 | Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to read, modify, or delete arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 5.3% | 💥 Exploit | SUN Java System Communications Express | 21/5/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book… | |
| Modificada | Alta (7.2) | 52% | 💥 Exploit | HP Data Protector Express | 14/5/2009 | 16/6/2026 | Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via… | |
| Modificada | Alta (7.5) | 1.7% | — | IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express | 5/5/2009 | 16/6/2026 | Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors. | |
| Modificada | Alta (10) | 3.3% | — | IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express | 5/5/2009 | 16/6/2026 | Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified… | |
| Modificada | Alta (10) | 71% | 💥 Exploit | IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express | 5/5/2009 | 16/6/2026 | Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Expressionengine | 26/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter. | |
| Modificada | Media (4.3) | 1.7% | — | SUN Java System Communications Express | 12/3/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field. | |
| Modificada | Alta (10) | 29% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager Express | 11/3/2009 | 16/6/2026 | Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value. | |
| Modificada | Media (4.3) | 12% | — | Microsoft Outlook Express | 11/12/2008 | 16/6/2026 | The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service… | |
| Modificada | Alta (10) | 11% | — | IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express | 31/10/2008 | 16/6/2026 | Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli… | |
| Modificada | Alta (7.1) | 27% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 13/8/2008 | 16/6/2026 | The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in… | |
| Modificada | Alta (9) | 35% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft SQL Server Express Edition | 8/7/2008 | 16/6/2026 | Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement. | |
| Modificada | Alta (9) | 62% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft SQL Server Express Edition | 8/7/2008 | 16/6/2026 | Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression. | |
| Modificada | Alta (10) | 2.1% | — | Oracle Application Express | 16/4/2008 | 16/6/2026 | Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02. | |
| Modificada | Media (5.5) | 2.1% | — | Oracle Application Express | 16/4/2008 | 16/6/2026 | Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that APEX01… | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Weblogic ExpressBEA Systems Weblogic Server | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL. | |
| Modificada | Media (6) | 10.0% | — | BEA Weblogic ServerBEA Systems Weblogic Express | 22/2/2008 | 16/6/2026 | Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors. | |
| Modificada | Alta (10) | 8.5% | — | IBM Tivoli Storage Manager Express | 12/1/2008 | 16/6/2026 | Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value. |