Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
–

718 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)5.2%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods…
ModificadaAlta (9.3)9.5%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird+114/4/200616/6/2026
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
ModificadaAlta (9.3)9.2%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.
ModificadaAlta (7.5)5.8%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of…
ModificadaAlta (7.5)4.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux14/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of…
AnalizadaAlta (9.3)10%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
nsHTMLContentSink.cpp in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that…
ModificadaAlta (7.5)4.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux14/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of…
ModificadaAlta (7.5)6.9%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird+114/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
ModificadaAlta (7.5)4.8%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of…
ModificadaAlta (9.3)8.4%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an…
ModificadaBaja (2.6)2.5%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
ModificadaMedia (6.4)2.0%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
ModificadaMedia (5.1)3.9%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
ModificadaMedia (5.8)2.8%—Mozilla FirefoxMozilla Seamonkey2/2/200616/6/2026
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
ModificadaMedia (5)4.1%—Mozilla FirefoxMozilla Seamonkey2/2/200616/6/2026
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
ModificadaAlta (7.5)4.9%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
ModificadaMedia (5.1)71%💥 ExploitMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
ModificadaAlta (10)12%—MIT KerberosMIT Kerberos 5SGI PropackSUN Seam+318/8/200416/6/2026
Múltiples desbordamientos de búfer en krb5_aname_to_localname en MIT Kerberos 5 (krb5) 1.3.3 y anteriores permite a atacantes remtos ejecutar código de su elección como root