Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 17% | 💥 Exploit | HP Java Sdk-rteSUN JDKSUN JRESymantec Enterprise Firewall+4 | 1/3/2005 | 16/6/2026 | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe classes and execute arbitrary code by using the reflection API… | |
| Modificada | Alta (10) | 16% | 💥 Exploit | GNU A2psSUN Java Desktop SystemSuse Linux | 10/1/2005 | 16/6/2026 | a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename. | |
| Modificada | Alta (10) | 6.3% | — | SUN Java 2 Micro EditionAISUN Kilobyte Virtual MachineAI | 31/12/2004 | 16/6/2026 | Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code. | |
| Modificada | Media (5) | 1.6% | — | SUN Java System Application ServerSUN Java System WEB Server | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate. | |
| Modificada | Alta (7.5) | 4.9% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. | |
| Modificada | Media (5.1) | 3.4% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817. | |
| Modificada | Alta (7.5) | 7.7% | — | SUN Java System WEB Proxy Server | 30/10/2004 | 16/6/2026 | Multiple buffer overflows in Sun Java System Web Proxy Server (formerly Sun ONE Proxy Server) 3.6 through 3.6 SP4 allow remote attackers to execute arbitrary code via unknown vectors, possibly CONNECT requests. | |
| Modificada | Alta (7.5) | 5.5% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+10 | 16/9/2004 | 16/6/2026 | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files. | |
| Modificada | Alta (7.5) | 4.3% | — | Linuxprinting.org Foomatic-filtersSUN Java Desktop SystemConectiva LinuxTrustix Secure Linux | 16/9/2004 | 16/6/2026 | Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete… | |
| Modificada | Alta (10) | 4.5% | — | SUN Java System Calendar Server | 27/7/2004 | 16/6/2026 | Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view. | |
| Modificada | Media (6.4) | 13% | — | Microsoft Java Virtual Machine | 27/7/2004 | 16/6/2026 | Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java." | |
| Modificada | Media (5) | 2.6% | — | SUN Java System Application ServerAI | 15/3/2004 | 16/6/2026 | Unknown vulnerability in Sun Java System Application Server 7.0 Update 2 and earlier, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Bajie Java Http Server | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inject arbitrary web script or HTML via (1) the query string to test.txt, (2) the guestName parameter to the custMsg servlet, or (3) the cookiename parameter to the CookieExample servlet. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | SUN Java Plug-in | 31/12/2003 | 16/6/2026 | The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to share variables, which violates the Java security model and could allow remote attackers to read or write data belonging to a signed applet. | |
| Modificada | Baja (2.1) | 0.80% | 💥 Exploit | SUN Java | 31/12/2003 | 16/6/2026 | Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the ClassDepth function with a null parameter, which causes a crash instead of generating a null pointer exception. | |
| Modificada | Media (6.4) | 5.8% | 💥 Exploit | SUN Java Plug-in | 31/12/2003 | 16/6/2026 | Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDocument method in the org.apache.crimson.tree.XmlDocument class, which violates the Java security model. | |
| Modificada | Media (4.3) | 2.0% | — | Bajie Java Http Server | 31/12/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Bajie Http Web Server 0.95zxe, 0.95zxc, and possibly others, allows remote attackers to inject arbitrary web script or HTML via the query string, which is reflected in an error message. | |
| Modificada | Alta (7.5) | 4.6% | — | Oracle JRESUN Java WEB StartSUN Jsse | 31/12/2003 | 16/6/2026 | X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper… | |
| Modificada | Alta (7.5) | 1.8% | — | SUN Java WEB Start | 31/12/2002 | 16/6/2026 | Unknown vulnerability in Java web start 1.0.1_01, 1.0.1, 1.0 and 1.0.1.01 (HP-UX 11.x only) allows attackers to gain access to restricted resources via unknown attack vectors. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Symantec Java | 31/12/2002 | 16/6/2026 | Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute arbitrary Java commands via an applet that uses a jump call, which is not correctly compiled by the JIT compiler. | |
| Modificada | Media (5) | 18% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL. | |
| Modificada | Alta (7.5) | 21% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the… | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices)… |