Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
951 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to… | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter,… | |
| Modificada | Alta (7.5) | 22% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages… | |
| Modificada | Media (5) | 17% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. | |
| Modificada | Media (5) | 20% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass. | |
| Modificada | Media (6.4) | 14% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. | |
| Modificada | Alta (7.5) | 27% | — | HP Java Jre-jdkMicrosoft Virtual MachineSUN JDKSUN JRE+1 | 19/3/2002 | 16/6/2026 | Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other… | |
| Modificada | Alta (7.5) | 2.1% | — | Apple MAC OS Runtime FOR JavaSUN JDKSUN JRESUN SDK | 31/12/2001 | 16/6/2026 | Java Runtime Environment (JRE) and SDK 1.2 through 1.3.0_04 allows untrusted applets to access the system clipboard. | |
| Modificada | Alta (7.5) | 1.7% | — | SUN Java Plug-inSUN JRE | 31/8/2001 | 16/6/2026 | Java Plugin 1.4 for JRE 1.3 executes signed applets even if the certificate is expired, which could allow remote attackers to conduct unauthorized activities via an applet that has been signed by an expired certificate. | |
| Modificada | Media (6.8) | 2.7% | — | IBM Visualage FOR Java | 2/7/2001 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in VisualAge for Java 3.5 Professional allows remote attackers to execute JavaScript on other clients via the URL, which injects the script in the resulting error message. | |
| Modificada | Media (5) | 1.6% | — | SUN Javaserver WEB DEV KIT | 18/6/2001 | 16/6/2026 | Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory. | |
| Modificada | Alta (7.5) | 7.9% | 💥 Exploit | Bajie Java Http Server | 3/5/2001 | 16/6/2026 | Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist. | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Bajie Java Http Server | 3/5/2001 | 16/6/2026 | UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program. | |
| Modificada | Media (5) | 2.4% | — | Free Java WEB Server | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Baja (2.6) | 1.5% | — | Apple MAC OS Runtime FOR Java | 12/2/2001 | 16/6/2026 | Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | SUN Hotjava Browser | 19/12/2000 | 23/9/2026 | HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named window. | |
| Modificada | Alta (10) | 6.0% | — | SUN Java System WEB Server | 14/11/2000 | 16/6/2026 | The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag. | |
| Modificada | Media (5) | 1.5% | — | Bajie Java Http Server | 20/10/2000 | 16/6/2026 | The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root. | |
| Modificada | Alta (10) | 2.6% | — | Apple MAC OS Runtime FOR Java | 20/10/2000 | 16/6/2026 | The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model. | |
| Modificada | Media (5) | 1.9% | — | Bajie Java Http Server | 20/10/2000 | 16/6/2026 | Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files via a URL that contains a "....", a variant of the dot dot directory traversal attack. | |
| Modificada | Alta (7.5) | 3.8% | — | SUN Java System WEB Server | 12/7/2000 | 16/6/2026 | The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet. | |
| Modificada | Alta (9.3) | 7.2% | — | Microsoft Java Virtual Machine | 21/10/1999 | 16/6/2026 | The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. | |
| Modificada | Alta (7.5) | 3.6% | — | Netscape CommunicatorNetscape NavigatorSUN Java | 1/3/1999 | 16/6/2026 | The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. | |
| Modificada | Alta (10) | 8.9% | 💥 Exploit | Java WEB ServerAI | 1/1/1999 | 16/6/2026 | The Java Web Server would allow remote users to obtain the source code for CGI programs. |