Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
729 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 74% | 💥 Exploit | Microsoft Outlook Express | 14/6/2005 | 16/6/2026 | Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (5) | 1.6% | — | Apple Airport ExpressApple Airport Extreme | 2/5/2005 | 16/6/2026 | Apple AirPort Express prior to 6.1.1 and Extreme prior to 5.5.1, configured as a Wireless Data Service (WDS), allows remote attackers to cause a denial of service (device freeze) by connecting to UDP port 161 and before link-state change occurs. | |
| Modificada | Alta (7.5) | 3.3% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive. | |
| Modificada | Alta (7.5) | 3.5% | — | Ipswitch Imail Express | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." | |
| Modificada | Media (4.3) | 1.3% | — | Express-web Content Management System | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Express-Web Content Management System (CMS) allow remote attackers to steal cookie-based authentication information and possibly perform other exploits via the (1) n, (2) b, (3) e, or (4) a parameters to default.asp, (5) the Referer header in an HTTP request to… | |
| Modificada | Media (5) | 26% | — | Microsoft Outlook Express | 31/12/2004 | 16/6/2026 | Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information. | |
| Modificada | Media (5.8) | 8.6% | — | Microsoft Outlook Express | 31/12/2004 | 16/6/2026 | Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top". | |
| Modificada | Media (5) | 11% | 💥 Exploit | F-secure Anti-virusF-secure FOR FirewallsF-secure Internet SecurityF-secure Personal Express+1 | 31/12/2004 | 16/6/2026 | Multiple interpretation error in various F-Secure Anti-Virus products, including Workstation 5.43 and earlier, Windows Servers 5.50 and earlier, MIMEsweeper 5.50 and earlier, Anti-Virus for Linux Servers and Gateways 4.61 and earlier, and other products, allows remote attackers to bypass antivirus protection via a… | |
| Modificada | Alta (7.8) | 2.3% | — | First Virtual Communications Click TO Meet ExpressFirst Virtual Communications Click TO Meet PremierFirst Virtual Communications Conference ServerFirst Virtual Communications V-gate | 31/12/2004 | 16/6/2026 | Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference Server, and V-Gate allow remote attackers to cause a denial of service, as demonstrated by the NISCC/OUSPG PROTOS test… | |
| Modificada | Alta (7.5) | 1.5% | — | BEA Weblogic ServerAIBEA Weblogic ExpressAI | 31/12/2004 | 16/6/2026 | The Web Services fat client for BEA WebLogic Server and Express 7.0 SP4 and earlier, when using 2-way SSL and multiple certificates to connect to the same URL, may use the incorrect identity after the first connection, which could allow users to gain privileges. | |
| Modificada | Media (5) | 59% | 💥 Exploit | Nortel IP Softphone 2050Nortel Media Communication Server 5100Nortel Media Communication Server 5200Nortel Media Processing Server+15 | 23/12/2004 | 16/6/2026 | The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number… | |
| Modificada | Media (6.4) | 4.1% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Múltiples vulnerabilidades de atravesamiento de directorios en LHA 1.14 permite a atacantes locales o usuarios locales crear ficheros arbitrarios mediante un archivo LHA conteniendo nombres de fichero con secuencias (1) ".." (punto punto) o (2) rutas absolutas con barra inicial doble ("//ruta/absoluta"). | |
| Modificada | Alta (10) | 10% | — | Clearswift MailsweeperF-secure Anti-virusF-secure FOR FirewallsF-secure Internet Security+9 | 18/8/2004 | 16/6/2026 | Múltiples desbordamientos de búfer basados en la pila en la función get_header de header.c de LHA 1.14 utilizado en productos como Barracuda Spam Firewall, permite a atacantes remotos o a usuarios locales ejecutar código arbitrario mediante nombres de fichero o de directorio largos en un archivo LHA, lo que dispara el… | |
| Modificada | Media (5) | 16% | — | Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+1 | 6/8/2004 | 16/6/2026 | Microsoft Outlook Express 5.5 y 6 permiten a atacantes causar una denegación de servicio (caída de la aplicación) mediante una cabecera de correo electrónico malformada. | |
| Modificada | Media (5) | 17% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerMicrosoft OutlookMicrosoft Outlook Express | 6/8/2004 | 16/6/2026 | Versiones desconocidas de Internet Explorer y Outlook permiten a atacantes remotos suplantar URL legítimas en la barra de estado mediante etiquetas A HREF con valores "alt" modificados que apuntan al sitio legítimo, combinado con un mapa de imagen cuyo HREF apunta al sitio malicioso, lo que facilita ataques de… | |
| Modificada | Alta (10) | 63% | 💥 Exploit | Microsoft Outlook Express | 4/5/2004 | 16/6/2026 | El Manejador del protocolo MHTML en Microsoft Outlook Express 5.5 SP2 a Outlook Express 6 SP1 permite a atacantes remotos eludir restricciones de dominio y ejecutar código arbitrario, como se ha demostrado en Internet Explorer usando código script en un archivo de ayuda compilada (CHM) te hace referencia a manejadores… | |
| Modificada | Alta (10) | 3.8% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247. | |
| Modificada | Media (5) | 2.4% | — | Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+13 | 21/1/2004 | 16/6/2026 | Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning. | |
| Modificada | Alta (8.8) | 16% | 💥 Exploit | Microsoft OutlookMicrosoft Outlook Express | 31/12/2003 | 16/6/2026 | Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077. | |
| Modificada | Alta (7.5) | 5.1% | — | Iptel SIP Express Router | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. | |
| Modificada | Media (5) | 6.0% | — | Microsoft Outlook Express | 16/6/2003 | 16/6/2026 | El cliente IMAP para Outlook Express 6.00.2800.1106 permite que servidores IMAP dañinos provoquen una denegación de servicio (caída) mediante ciertos valores literales muy grandes que provocan errores de desbordamiento de enteros. | |
| Modificada | Media (5) | 3.4% | — | Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+4 | 16/6/2003 | 16/6/2026 | El cliente IMAP para Sylpheed 0.8.11 permite que servidores IMAP remotos dañinos originen una denegación de servicio (caída) mediante ciertos tamaños literales muy largos que causan desbordamientos de búfer de enteros. | |
| Modificada | Baja (3.8) | 1.3% | — | Microsoft Outlook Express | 31/12/2002 | 16/6/2026 | Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email. | |
| Modificada | Media (5) | 22% | 💥 Exploit | Microsoft Outlook Express | 31/12/2002 | 16/6/2026 | Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link. |