Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
791 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.0% | — | KAF Oseo Quick AND Dirty Phpsource Printer | 6/7/2005 | 16/6/2026 | Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences. | |
| Modificada | Alta (7.5) | 1.1% | — | Etoshop Dynamic BIZ Website Builder Quickweb | 5/7/2005 | 16/6/2026 | SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Open Solution Quick.cart | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter. | |
| Modificada | Media (5) | 1.4% | — | Open Solution Quick.forum | 14/5/2005 | 16/6/2026 | Quick.Forum 2.1.6 stores potentially sensitive information such as usernames, banned IP addresses, censored words, and backups under the web document root, which allows remote attackers to obtain that information via a direct request to (1) db/users.txt, (2) db/banList.txt, (3) db/censureWords.txt, or (4) backup files. | |
| Modificada | Media (4.3) | 1.2% | — | Open Solution Quick.forum | 14/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action. | |
| Modificada | Media (5) | 2.0% | — | Apple Quicktime | 12/5/2005 | 16/6/2026 | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | |
| Modificada | Alta (7.5) | 1.3% | — | Open Solution Quick.forum | 11/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory. | |
| Modificada | Alta (7.5) | 1.2% | — | Open Solution Quick.cart | 11/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be vulnerable to SQL injection | |
| Modificada | Media (5) | 1.2% | — | Apple Quicktime Pictureviewer | 2/5/2005 | 16/6/2026 | PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow. | |
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Apple Quicktime Pictureviewer | 2/5/2005 | 16/6/2026 | Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data. | |
| Modificada | Media (5) | 1.2% | — | Apple Quicktime | 1/3/2005 | 16/6/2026 | Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation. | |
| Modificada | Alta (7.5) | 1.1% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 27/1/2005 | 16/6/2026 | AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets. | |
| Modificada | Media (5) | 0.97% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 27/1/2005 | 16/6/2026 | AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box. | |
| Modificada | Media (5) | 1.3% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 10/1/2005 | 16/6/2026 | Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Quicksilver Master OF Orion IIIAI | 31/12/2004 | 16/6/2026 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (server crash) via multiple connections with long nicknames, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 1.7% | — | Quicksilver Master OF Orion III | 31/12/2004 | 16/6/2026 | Master of Orion III 1.2.5 and earlier allows remote attackers to cause a denial of service (game exit) via a data packet that contains a large size specifier, which causes a large memory allocation to fail. | |
| Modificada | Media (4) | 1.2% | — | Pablo Software Solutions Quick N Easy FTP Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Pablo Software Solutions Quick 'n Easy FTP Server 1.77, and possibly earlier versions, allows remote authenticated users to determine the existence of arbitrary files via a .. (dot dot) in the DEL command, which triggers different error messages depending on whether the file exists… | |
| Modificada | Alta (7.5) | 1.9% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 3/12/2004 | 16/6/2026 | Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization. | |
| Modificada | Alta (7.5) | 3.4% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file. | |
| Modificada | Baja (2.1) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode. | |
| Modificada | Media (5) | 1.6% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles. | |
| Modificada | Baja (2.1) | 0.35% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user. | |
| Modificada | Media (4.6) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users. | |
| Modificada | Alta (7.5) | 1.7% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information. | |
| Modificada | Baja (2.1) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session. |