Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2666▼ 407 respecto a la semana anterior
Críticas / altas1266▼ 215 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)215▼ 115 respecto a la semana anterior
772 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.9% | — | Mozilla FirefoxMozilla SuiteMozilla SeamonkeyCanonical Ubuntu Linux | 14/4/2006 | 16/6/2026 | Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants… | |
| Modificada | Alta (9.3) | 9.5% | — | Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird+1 | 14/4/2006 | 16/6/2026 | Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method. | |
| Modificada | Alta (7.5) | 4.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux | 14/4/2006 | 16/6/2026 | Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of… | |
| Modificada | Media (6.8) | 5.2% | — | Mozilla FirefoxMozilla SuiteMozilla SeamonkeyMozilla Thunderbird | 14/4/2006 | 16/6/2026 | Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods… | |
| Modificada | Media (4.3) | 2.9% | 💥 Exploit | Fuzzymonkey MY BlogM Blom Html-bbcode | 16/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag. | |
| Modificada | Media (6.4) | 2.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. | |
| Modificada | Media (5.8) | 2.8% | — | Mozilla FirefoxMozilla Seamonkey | 2/2/2006 | 16/6/2026 | The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read. | |
| Modificada | Media (5.1) | 3.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas. | |
| Modificada | Alta (7.5) | 4.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory. | |
| Modificada | Media (5) | 4.1% | — | Mozilla FirefoxMozilla Seamonkey | 2/2/2006 | 16/6/2026 | The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file. | |
| Modificada | Media (5.1) | 71% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla Thunderbird | 2/2/2006 | 16/6/2026 | Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption. | |
| Modificada | Alta (7.5) | 1.2% | — | Widgetmonkey Php-addressbook | 11/12/2005 | 16/6/2026 | Vulnerabilidad de inyección de SQL en view.php en PHP-addressbook 1.2 permite a atacantes remotos ejecutar órdenes SQL de su elección mediante el parámetro "id". | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Greasemonkey | 4/8/2005 | 16/6/2026 | Greasemonkey anterior a la 0.3.5 permite que servidores web remotos: (1) lean ficheros arbitraios (función GM_xmlhttpRequest), (2) liste scripts instalados usando GM_scripts, y (3) obtenga información valiosa mediante GM_setValue y GM_getValue. | |
| Modificada | Media (5) | 1.6% | — | Monkey-project Monkey | 2/5/2005 | 16/6/2026 | Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file. | |
| Modificada | Alta (7.5) | 2.7% | — | Monkey-project Monkey | 14/4/2005 | 16/6/2026 | Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error"). | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Monkey-project Monkey | 23/11/2004 | 16/6/2026 | La función get_real_string de Monkey HTTPD Daemon (monkeyd) 0.8.1 y anteriores permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición HTTP con una secuencia de caractéres "%" y un campo Host no presente. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Fuzzymonkey Myclassifieds | 31/12/2003 | 16/6/2026 | SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Media (5) | 2.4% | — | Monkey-project Monkey | 31/12/2003 | 16/6/2026 | The Post_Method function in Monkey HTTP Daemon before 0.6.2 allows remote attackers to cause a denial of service (crash) via a POST request without a Content-Type header. | |
| Modificada | Alta (7.5) | 5.2% | — | Monkey-project Monkey | 12/5/2003 | 16/6/2026 | Desbordamiento de búfer en la función PostMethod() de Monkey HTTP Daemon (monkeyd) 0.6.1 y anteriores permite a atacantes remotos ejecutar código arbitrario mediante una petición POST con un cuerpo largo. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | Monkey-project Monkey | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (dot dot) sequences. | |
| Modificada | Media (5) | 4.0% | 💥 Exploit | Monkey-project Monkey | 31/12/2002 | 16/6/2026 | The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value. | |
| Modificada | Media (4.3) | 3.4% | 💥 Exploit | Monkey-project Monkey | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML via (1) the URL or (2) a parameter to test2.pl. |