Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2847▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 166 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | THE PHP Group Pear Html Quickform Controller | 31/12/2005 | 16/6/2026 | The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors. | |
| Modificada | Alta (7.5) | 4.1% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values. | |
| Modificada | Alta (7.5) | 3.2% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Apple Quicktime | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field. | |
| Modificada | Alta (7.5) | 7.3% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags. | |
| Modificada | Alta (7.5) | 8.0% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files. | |
| Modificada | Media (4.3) | 1.4% | — | JL Webworks Quickblogger | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section. | |
| Modificada | Alta (7.5) | 4.0% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Quicksquare Development Honeycomb ArchiveQuicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in CategoryResults.cfm in Honeycomb Archive and Honeycomb Archive Enterprise 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) series, (2) cat_parent, (3) cat, and (4) div parameters. | |
| Modificada | Media (4.3) | 1.2% | — | Quicksquare Development Honeycomb Archive Enterprise | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Honeycomb Archive Enterprise 3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified search parameters, possibly the keyword parameter in search.cfm. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Quickpaypro | 15/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en QuickPayPro 3.1 permiten a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro (1) popupid en popups.edit.php; los parámetros (2) so, (3) sb, y (4) nr) en customer.tickets.view.php; el parámetro (5) subrackingid en subscribers.tracking.edit.php;… | |
| Modificada | Media (4.3) | 1.3% | — | Quickpaypro | 15/12/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en QuickPayPro 3.1 permiten a atacantes remotos inyectar 'script' web o HTML de su elección mediante varios campos, como aquellos en (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, y (3) mycompany/categories.php. | |
| Modificada | Alta (7.5) | 8.8% | — | Apple ItunesApple Quicktime | 8/12/2005 | 16/6/2026 | Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified… | |
| Modificada | Media (5.1) | 1.1% | — | Quicksilver Forums | 6/12/2005 | 16/6/2026 | SQL injection vulnerability in Quicksilver Forums before 1.5.1 allows remote attackers to execute arbitrary SQL commands via the HTTP_USER_AGENT header. | |
| Modificada | Media (4.3) | 1.3% | — | Coastal Data Management E-quick Cart | 22/11/2005 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en e-Quick Cart permiten a atacantes remotos inyectar 'script' web arbitrario o HTML mediante (1) el parámetro "strgifttoname" en shopgift.asp, (2) el parámetro "strfirstname" shopmaillist.asp, (3) el parámetro "strpid" en… | |
| Modificada | Alta (7.5) | 1.5% | — | Coastal Data Management E-quick Cart | 22/11/2005 | 16/6/2026 | Múltiples vulnerabilidades de inyección de SQL en e-Quick Cart permiten a atacantes remotos ejecutar comandos SQL de su elección mediante (1) el parámetro "productid" en shopaddtocart.asp, (2) el parámetro "strpemail" en shopprojectlogin.asp, y (3) el parámetro "id" en shoptellafriend.asp. | |
| Modificada | Media (4.3) | 1.2% | 💥 Exploit | Symantec Veritas Cluster ServerSymantec Veritas Sanpoint Control QuickstartSymantec Veritas Storage FoundationSymantec Veritas Storage Foundation Cluster File System | 16/11/2005 | 16/6/2026 | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog,… | |
| Modificada | Media (5.1) | 2.1% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes." | |
| Modificada | Media (5.1) | 4.2% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion. | |
| Modificada | Media (5.1) | 2.1% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string. | |
| Modificada | Baja (2.6) | 1.8% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference. | |
| Modificada | Media (5) | 7.8% | — | CAT Quick Heal | 1/11/2005 | 16/6/2026 | Multiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by… | |
| Modificada | Alta (7.5) | 4.7% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 26/10/2005 | 16/6/2026 | The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5.1) | 14% | — | CAT Quick Heal | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected… | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Pablo Software Solutions Quick N Easy FTP Server | 5/8/2005 | 16/6/2026 | Quick 'n Easy FTP Server 3.0 permite que atacantes remotos causen una denegación de servicio (caída de la aplicación o excesivo consumo de CPU) mediante un comando USER demasiado largo. |