Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 4.5% | — | Invensys Wonderware Archestra Configuration Access Component Activex ControlInvensys Wonderware Application Server | 5/8/2010 | 16/6/2026 | Stack-based buffer overflow in the IConfigurationAccess interface in the Invensys Wonderware Archestra ConfigurationAccessComponent ActiveX control in Wonderware Application Server (WAS) before 3.1 SP2 P01, as used in the Wonderware Archestra Integrated Development Environment (IDE) and the InFusion Integrated… | |
| Modificada | Alta (9.3) | 6.9% | 💥 Exploit | Barcodewiz Barcode Activex Control | 5/8/2010 | 16/6/2026 | Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method. | |
| Modificada | Alta (9.3) | 9.4% | 💥 Exploit | Topazsystems Sigplus PRO Activex Control | 5/8/2010 | 16/6/2026 | Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method. | |
| Modificada | Alta (10) | 3.2% | — | Gigabyte Dldrv2 Activex Control | 2/8/2010 | 16/6/2026 | Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via the item argument. | |
| Modificada | Alta (10) | 1.8% | — | Gigabyte Dldrv2 Activex Control | 2/8/2010 | 16/6/2026 | The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the… | |
| Modificada | Alta (10) | 4.6% | — | Creative Autoupdate Engine Activex ControlCreative Autoupdate | 15/6/2010 | 16/6/2026 | Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method. | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Viscomsoft Movie Player PRO SDK Activex | 18/1/2010 | 16/6/2026 | Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method. | |
| Modificada | Alta (8.8) | 5.1% | 💥 Exploit | Softcab Sound Converter Activex | 29/12/2009 | 16/6/2026 | Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers to create or overwrite arbitrary files via the SaveFormat method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | CA Etrust Pestpatrole Ppctl.dll Activex | 8/12/2009 | 16/6/2026 | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method. | |
| Modificada | Alta (9.3) | 4.8% | — | Larts Uploader Activex Control | 3/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value. | |
| Modificada | Alta (8.8) | 8.9% | 💥 Exploit | AOL Superbuddy Activex Control | 9/10/2009 | 16/6/2026 | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method. | |
| Modificada | Alta (9.3) | 4.8% | 💥 Exploit | Chilkatsoft Chilkat Imap Activex Control | 21/8/2009 | 16/6/2026 | Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Avax-software Avax Vector Activex | 8/7/2009 | 16/6/2026 | Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property. | |
| Modificada | Alta (9.3) | 4.1% | — | Ebay Enhanced Picture Uploader Activex Control | 9/6/2009 | 16/6/2026 | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property. | |
| Modificada | Alta (9.3) | 5.6% | — | Dlink Mpeg4 Viewer Activex Control | 20/5/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Alta (8.8) | 1.7% | — | Versalsoft Http File Upload Activex Control | 7/4/2009 | 16/6/2026 | Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method. | |
| Modificada | Alta (7.8) | 5.7% | 💥 Exploit | Precisionid Data Matrix Barcode Activex Control | 1/4/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods. | |
| Modificada | Alta (9.3) | 8.8% | 💥 Exploit | Geovision Liveaudio Activex Control | 25/3/2009 | 16/6/2026 | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | IBM Access Support Activex Control | 25/3/2009 | 16/6/2026 | Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 5.5% | 💥 Exploit | Geovision Livex Activex Control | 10/3/2009 | 16/6/2026 | Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods. | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | Sopcast Sopcore Activex Control | 4/3/2009 | 16/6/2026 | Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method. | |
| Modificada | Alta (9.3) | 8.8% | 💥 Exploit | Eztools-software WEB ON Windows Activex | 2/2/2009 | 16/6/2026 | Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute method, (3) read from the registry via unspecified vectors, and… | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | MW6 Technologies Barcode Activex | 27/1/2009 | 16/6/2026 | Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property. | |
| Modificada | Alta (9.3) | 16% | — | SapguiSimba Technologies Mdrmsap Activex Control | 10/11/2008 | 16/6/2026 | Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | Chilkat Software Chilkat Crypt Activex Control | 10/11/2008 | 16/6/2026 | Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in… |