Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
–

772 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)3.9%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyCanonical Ubuntu Linux14/4/200616/6/2026
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants…
ModificadaAlta (9.3)9.5%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird+114/4/200616/6/2026
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
ModificadaAlta (7.5)4.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux14/4/200616/6/2026
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of…
ModificadaMedia (6.8)5.2%—Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird14/4/200616/6/2026
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods…
ModificadaMedia (4.3)2.9%💥 ExploitFuzzymonkey MY BlogM Blom Html-bbcode16/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.
ModificadaMedia (6.4)2.0%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.
ModificadaMedia (5.8)2.8%—Mozilla FirefoxMozilla Seamonkey2/2/200616/6/2026
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
ModificadaMedia (5.1)3.9%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.
ModificadaAlta (7.5)4.9%—Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
ModificadaMedia (5)4.1%—Mozilla FirefoxMozilla Seamonkey2/2/200616/6/2026
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.
ModificadaMedia (5.1)71%💥 ExploitMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird2/2/200616/6/2026
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.
ModificadaAlta (7.5)1.2%—Widgetmonkey Php-addressbook11/12/200516/6/2026
Vulnerabilidad de inyección de SQL en view.php en PHP-addressbook 1.2 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro "id".
ModificadaMedia (5)8.5%💥 ExploitGreasemonkey4/8/200516/6/2026
Greasemonkey anterior a la 0.3.5 permite que servidores web remotos: (1) lean ficheros arbitraios (función GM_xmlhttpRequest), (2) liste scripts instalados usando GM_scripts, y (3) obtenga información valiosa mediante GM_setValue y GM_getValue.
ModificadaMedia (5)1.6%—Monkey-project Monkey2/5/200516/6/2026
Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file.
ModificadaAlta (7.5)2.7%—Monkey-project Monkey14/4/200516/6/2026
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error").
ModificadaMedia (5)3.7%💥 ExploitMonkey-project Monkey23/11/200416/6/2026
La función get_real_string de Monkey HTTPD Daemon (monkeyd) 0.8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición HTTP con una secuencia de caractéres "%" y un campo Host no presente.
ModificadaMedia (6.8)1.1%💥 ExploitFuzzymonkey Myclassifieds31/12/200316/6/2026
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter.
ModificadaMedia (5)2.4%—Monkey-project Monkey31/12/200316/6/2026
The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header.
ModificadaAlta (7.5)5.2%—Monkey-project Monkey12/5/200316/6/2026
Desbordamiento de búfer en la función PostMethod() de Monkey HTTP Daemon (monkeyd) 0.6.1 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante una petición POST con un cuerpo largo.
ModificadaMedia (5)7.6%💥 ExploitMonkey-project Monkey31/12/200216/6/2026
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences.
ModificadaMedia (5)4.0%💥 ExploitMonkey-project Monkey31/12/200216/6/2026
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.
ModificadaMedia (4.3)3.4%💥 ExploitMonkey-project Monkey31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl.
Orbitaley — Vulnerabilidades