Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—PHP Lite Calendar Express5/12/200516/6/2026
Multiple SQL injection vulnerabilities in PHP Lite Calendar Express 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid and (2) catid parameters to (a) day.php, (b) week.php, (c) month.php, and (d) year.php.
ModificadaAlta (7.5)1.4%—Sensation Designs Kbase Express5/12/200516/6/2026
SQL injection vulnerability in KBase Express 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to category.php and (2) search parameters to search.php.
ModificadaAlta (7.8)4.9%—Checkpoint Check PointCheckpoint ExpressCheckpoint Firewall-1Checkpoint Vpn-1+118/11/200516/6/2026
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666,…
ModificadaMedia (5)2.3%—SUN Java System Communications Express3/11/200516/6/2026
Unspecified vulnerability in Sun Java System Communications Express 2005Q1 and 2004Q2 allows local and remote attackers to read sensitive information from configuration files.
ModificadaAlta (7.5)1.8%—Rockliffe Mailsite Express2/11/200516/6/2026
Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific extensions, such as (1) .unk, (2) .asa, and possibly (3) .htr and (4) .aspx, which are not filtered like the .asp extension.
ModificadaMedia (4.3)2.4%—Rockliffe Mailsite Express2/11/200516/6/2026
Rockliffe MailSite Express before 6.1.22, with the option to save login information enabled, saves user passwords in plaintext in cookies, which allows local users to obtain passwords by reading the cookie file, or remote attackers to obtain the cookies via cross-site scripting (XSS) vulnerabilities.
ModificadaMedia (4.3)1.5%—Rockliffe Mailsite Express2/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.
ModificadaMedia (5)1.6%—Rockliffe Mailsite Express2/11/200516/6/2026
Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.
ModificadaMedia (5)1.6%—Rockliffe Mailsite Express23/10/200516/6/2026
Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
ModificadaMedia (5)1.4%—Rockliffe Mailsite Express23/10/200516/6/2026
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
ModificadaMedia (5)13%—Microsoft Outlook Express12/7/200516/6/2026
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
ModificadaAlta (7.5)74%💥 ExploitMicrosoft Outlook Express14/6/200516/6/2026
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaMedia (5)1.6%—Apple Airport ExpressApple Airport Extreme2/5/200516/6/2026
Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs.
ModificadaAlta (7.5)3.3%—F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper2/5/200516/6/2026
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
ModificadaAlta (7.8)2.3%—First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate31/12/200416/6/2026
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test…
ModificadaMedia (5.8)8.6%—Microsoft Outlook Express31/12/200416/6/2026
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top".
ModificadaMedia (5)26%—Microsoft Outlook Express31/12/200416/6/2026
Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information.
ModificadaMedia (4.3)1.3%—Express-web Content Management System31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to…
ModificadaAlta (7.5)1.5%—BEA Weblogic ServerAIBEA Weblogic ExpressAI31/12/200416/6/2026
The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges.
ModificadaAlta (7.5)3.5%—Ipswitch Imail Express31/12/200416/6/2026
Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text."
ModificadaMedia (5)11%💥 ExploitF-secure Anti-virusF-secure FOR FirewallsF-secure Internet SecurityF-secure Personal Express+131/12/200416/6/2026
Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a…
ModificadaMedia (5)59%💥 ExploitNortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+1523/12/200416/6/2026
The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number…
ModificadaAlta (10)10%—Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+918/8/200416/6/2026
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the…
ModificadaMedia (6.4)4.1%—Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+918/8/200416/6/2026
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").