Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

740 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)17%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerMicrosoft OutlookMicrosoft Outlook Express6/8/200416/6/2026
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
ModificadaMedia (5)16%—Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+16/8/200416/6/2026
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
ModificadaAlta (10)63%💥 ExploitMicrosoft Outlook Express4/5/200416/6/2026
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers…
ModificadaAlta (10)3.8%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.
ModificadaMedia (5)2.4%—Cisco Emergency ResponderCisco IP Call Center Express EnhancedCisco IP Call Center Express StandardCisco IP Interactive Voice Response+1321/1/200416/6/2026
Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, allows remote attackers to cause a denial of service (CPU consumption) via arbitrary packets to TCP port 14247, as demonstrated using port scanning.
ModificadaAlta (7.5)5.1%—Iptel SIP Express Router31/12/200316/6/2026
The Session Initiation Protocol (SIP) implementation in IPTel SIP Express Router 0.8.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite.
ModificadaAlta (8.8)16%💥 ExploitMicrosoft OutlookMicrosoft Outlook Express31/12/200316/6/2026
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs via an HTML email with the CODEBASE parameter set to the program, a vulnerability similar to CAN-2002-0077.
ModificadaMedia (5)3.4%—Microsoft Outlook ExpressMozillaMuttQualcomm Eudora+416/6/200316/6/2026
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
ModificadaMedia (5)6.0%—Microsoft Outlook Express16/6/200316/6/2026
The IMAP Client for Outlook Express 6.00.2800.1106 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
ModificadaBaja (3.8)1.3%—Microsoft Outlook Express31/12/200216/6/2026
Outlook Express 6.0 does not delete messages from dbx files, even when a user empties the Deleted items folder, which allows local users to read other users email.
ModificadaMedia (5)22%💥 ExploitMicrosoft Outlook Express31/12/200216/6/2026
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.
ModificadaAlta (7.5)22%💥 ExploitMicrosoft Outlook Express28/10/200216/6/2026
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a digitally signed email with a long "From" address, which triggers the overflow when the user views or previews the message.
ModificadaMedia (6.8)16%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+54/10/200216/6/2026
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate…
ModificadaAlta (7.5)12%—Microsoft Outlook Express31/5/200216/6/2026
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which…
ModificadaMedia (5)2.0%—Eshare Communications Inc. Eshare Expressions29/5/200216/6/2026
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.
ModificadaAlta (7.5)17%—Microsoft EntourageMicrosoft ExcelMicrosoft IEMicrosoft Office+222/4/200216/6/2026
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001,…
ModificadaAlta (7.5)14%—Microsoft Outlook Express31/12/200116/6/2026
Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code.
ModificadaMedia (5)20%—Microsoft Outlook Express3/12/200116/6/2026
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.
ModificadaAlta (7.5)3.5%—Celtech Software Expressfs28/11/200116/6/2026
Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.
ModificadaAlta (7.5)12%—Microsoft Outlook Express12/9/200116/6/2026
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.
ModificadaAlta (7.5)20%💥 ExploitMicrosoft OutlookMicrosoft Outlook Express5/6/200116/6/2026
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in my address book" option enabled, do not notify the user when the "Reply-To" address is different than the "From" address, which could allow an untrusted remote attacker to spoof legitimate addresses…
ModificadaMedia (5)21%💥 ExploitMicrosoft Internet ExplorerMicrosoft OutlookMicrosoft Outlook Express2/6/200116/6/2026
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.
ModificadaAlta (7.5)6.7%—Microsoft OutlookMicrosoft Outlook Express3/5/200116/6/2026
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.
ModificadaAlta (7.5)27%💥 ExploitMicrosoft Internet ExplorerMicrosoft Outlook Express20/4/200116/6/2026
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).
ModificadaMedia (5)1.3%—Intel Express 510tIntel Express 520tIntel Express 550fIntel Express 550t14/11/200016/6/2026
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.
Orbitaley — Vulnerabilidades