Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
740 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 29% | — | IBM Tivoli Storage ManagerIBM Tivoli Storage Manager Express | 11/3/2009 | 16/6/2026 | Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value. | |
| Modificada | Media (4.3) | 12% | — | Microsoft Outlook Express | 11/12/2008 | 16/6/2026 | The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service… | |
| Modificada | Alta (10) | 11% | — | IBM Tivoli Storage Manager ClientIBM Tivoli Storage Manager Express | 31/10/2008 | 16/6/2026 | Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 through 5.4.2.2, and 5.5.0.0 through 5.5.0.91 in IBM Tivoli… | |
| Modificada | Alta (7.1) | 27% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 13/8/2008 | 16/6/2026 | The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in… | |
| Modificada | Alta (9) | 62% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft SQL Server Express Edition | 8/7/2008 | 16/6/2026 | Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression. | |
| Modificada | Alta (9) | 35% | — | Microsoft Data EngineMicrosoft SQL ServerMicrosoft SQL Server Desktop EngineMicrosoft SQL Server Express Edition | 8/7/2008 | 16/6/2026 | Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement. | |
| Modificada | Alta (10) | 2.1% | — | Oracle Application Express | 16/4/2008 | 16/6/2026 | Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02. | |
| Modificada | Media (5.5) | 2.1% | — | Oracle Application Express | 16/4/2008 | 16/6/2026 | Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01. NOTE: the previous information was obtained from the April 2008 CPU. Oracle has not commented on reliable researcher claims that APEX01… | |
| Modificada | Media (6) | 10.0% | — | BEA Weblogic ServerBEA Systems Weblogic Express | 22/2/2008 | 16/6/2026 | Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors. | |
| Modificada | Media (4.3) | 1.2% | — | BEA Systems Weblogic ExpressBEA Systems Weblogic Server | 22/2/2008 | 16/6/2026 | Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL. | |
| Modificada | Alta (10) | 8.5% | — | IBM Tivoli Storage Manager Express | 12/1/2008 | 16/6/2026 | Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value. | |
| Modificada | Media (4.3) | 1.3% | — | Expressionengine | 10/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Expressionengine | 10/1/2008 | 16/6/2026 | CRLF injection vulnerability in index.php in ExpressionEngine 1.2.1 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the URL parameter. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Tivoli Provisioning Manager Express | 17/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Provisioning Manager Express allow remote attackers to inject arbitrary web script or HTML via the (1) "assess modification," (2) user-id, and other unspecified fields to the /tpmx URI; or (3) involving unspecified vectors related to "error processing." | |
| Modificada | Media (5) | 1.2% | — | IBM Tivoli Provisioning Manager Express | 17/12/2007 | 16/6/2026 | IBM Tivoli Provisioning Manager Express provides unspecified information in error messages when (1) attempted duplication of a username occurs when creating an account or (2) when trying to login using a valid username, which makes it easier for remote attackers to enumerate usernames. | |
| Modificada | Media (6.4) | 2.5% | — | Pcre Perl-compatible Regular Expression LibraryApple MAC OS XApple MAC OS X Server | 7/11/2007 | 16/6/2026 | Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d"… | |
| Modificada | Baja (2.1) | 2.0% | — | Microsoft Expression Media | 16/10/2007 | 16/6/2026 | Microsoft Expression Media stores the catalog password in cleartext in the catalog IVC file, which allows local users to obtain sensitive information and gain access to the catalog by reading the IVC file. | |
| Modificada | Alta (9.3) | 55% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 9/10/2007 | 16/6/2026 | Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption. | |
| Modificada | Alta (9.3) | 6.6% | — | Broderbund Expressit 3dgreetings Player | 6/9/2007 | 16/6/2026 | Multiple buffer overflows in the Broderbund Expressit 3DGreetings Player ActiveX control could allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 13% | — | Microsoft OutlookMicrosoft Outlook Express | 27/7/2007 | 16/6/2026 | Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking… | |
| Modificada | Alta (7.5) | 1.0% | — | Iexpress Property PRO | 25/7/2007 | 16/6/2026 | SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (5) | 1.0% | — | Iexpress Munch PRO | 25/7/2007 | 16/6/2026 | SQL injection vulnerability in Munch Pro allows remote attackers to execute arbitrary SQL commands via the login field to /admin, a different vulnerability than CVE-2006-5880. | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | PHP Lite Calendar Express | 9/7/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the cid parameter to (1) login.php, (2) auth.php, and (3) subscribe.php. NOTE: the month.php, year.php, week.php, and day.php vectors are already covered by CVE-2005-4009. NOTE: the… | |
| Modificada | Alta (9.3) | 3.7% | — | F-secure Anti-virusF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server SecurityF-secure Internet Security+2 | 20/6/2007 | 16/6/2026 | Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive. | |
| Modificada | Media (4.3) | 25% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 12/6/2007 | 16/6/2026 | The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information… |