Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
108 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 7.7% | — | Nctsoft Nctaudioeditor Activex Control | 29/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 4.0% | — | Aurigma Image Uploader Activex ControlPiczo Imageuploader4 | 25/3/2008 | 16/6/2026 | Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Sony Axruploadserver Activex ControlSony Imagestation | 13/2/2008 | 16/6/2026 | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Aurigma Image Uploader Activex ControlFacebookFacebook Photouploader | 8/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties. | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Aurigma Image Uploader Activex ControlMyspaceuploader | 8/2/2008 | 16/6/2026 | Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property. | |
| Modificada | Alta (10) | 7.3% | 💥 Exploit | Ourgame.com GlworldOurgame.com Hangameplugincn18 Activex Control | 7/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited… | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Sejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control | 6/2/2008 | 16/6/2026 | Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | AOL YGP Piceditor Activex Control | 4/2/2008 | 16/6/2026 | Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5)… | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Streamaudio Chaincast Proxymanager Activex Control | 12/1/2008 | 16/6/2026 | Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method. | |
| Modificada | Alta (10) | 29% | — | Microsoft VFP OLE Server Activex Control | 11/1/2008 | 16/6/2026 | The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Gateway Cweblaunchctl Activex ControlGateway Weblaunch | 10/1/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are… | |
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | Ravware Flic Activex Control | 21/12/2007 | 16/6/2026 | Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Webex Communications Webex Gpccontainer Activex Control | 15/11/2007 | 16/6/2026 | Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method. | |
| Modificada | Alta (7.5) | 4.7% | — | Automated Solutions Modbus Slave Activex Control | 19/9/2007 | 16/6/2026 | Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502. | |
| Modificada | Alta (9.3) | 6.7% | — | Photochannel PNI Digital Media Upload Plugin Activex Control | 18/9/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 4.6% | 💥 Exploit | HP Photo Digital Imaging Activex Control | 10/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | Chilkat Software Chilkat ZIP Activex Control | 10/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method. | |
| Modificada | Alta (7.6) | 14% | 💥 Exploit | AMX Netlinx VNC Activex Control | 3/7/2007 | 16/6/2026 | Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values. | |
| Modificada | Media (6.4) | 8.8% | 💥 Exploit | HP Photo Digital Imaging Activex Control | 29/6/2007 | 16/6/2026 | Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method. | |
| Modificada | Alta (9.3) | 6.5% | — | Zoomify Viewer Activex Control | 11/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 44% | 💥 Exploit | Microsoft Internet ExplorerProvideo Camimage Activex Control | 7/6/2007 | 16/6/2026 | Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value. | |
| Modificada | Media (6.8) | 3.4% | — | Media Technology Group Cdpass Activex Control | 1/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method. | |
| Modificada | Alta (9.3) | 5.2% | — | BT Business Connect Webhelper Activex Control | 1/6/2007 | 16/6/2026 | Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 4.7% | 💥 Exploit | H+H Vcdapilibapi Activex ControlH+H Virtual CD | 24/5/2007 | 16/6/2026 | The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function. | |
| Modificada | Alta (10) | 4.6% | — | SKY Software Shcombobox Activex ControlSKY Software Shell Megapack Activex | 24/5/2007 | 16/6/2026 | Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… |