Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies Pdf417 Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies Datamatrix Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies 1D Barcode Decoder Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (9) | 7.1% | 💥 Exploit | MW6 Technologies Aztec Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Djvu Activex Control FOR Microsoft Office 2000 | 4/11/2008 | 16/6/2026 | Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties. | |
| Modificada | Alta (8.8) | 2.8% | 💥 Exploit | Visagesoft Expert PDF Viewer Activex | 4/11/2008 | 16/6/2026 | Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Dart Powertcp FTP FOR Activex | 22/10/2008 | 16/6/2026 | Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property. | |
| Modificada | Alta (9.3) | 8.7% | 💥 Exploit | Chilkat Software Chilkat XML Activex Control | 30/9/2008 | 16/6/2026 | The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited… | |
| Modificada | Media (6.8) | 59% | 💥 Exploit | Microsoft Office Snapshot Viewer Activex | 7/7/2008 | 16/6/2026 | The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use… | |
| Modificada | Alta (9.3) | 7.7% | — | Nctsoft Nctaudioeditor Activex Control | 29/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.8) | 6.0% | — | Alivemedia Alive MP3 WAV ConverterOnline Media Technologies Nctaudioeditor Activex ControlOnline Media Technologies Nctaudiostudio Activex ControlOrion Studios Cinematicmp3+2 | 29/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow… | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Chilkat Software Chilkathttp Activex | 2/4/2008 | 16/6/2026 | The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (9.3) | 4.0% | — | Aurigma Image Uploader Activex ControlPiczo Imageuploader4 | 25/3/2008 | 16/6/2026 | Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Sony Axruploadserver Activex ControlSony Imagestation | 13/2/2008 | 16/6/2026 | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (9.3) | 29% | — | Microsoft ActivexMicrosoft IEMicrosoft Internet Explorer | 12/2/2008 | 16/6/2026 | Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability." | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Aurigma Image Uploader Activex ControlFacebookFacebook Photouploader | 8/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties. | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Aurigma Image Uploader Activex ControlMyspaceuploader | 8/2/2008 | 16/6/2026 | Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property. | |
| Modificada | Alta (10) | 7.3% | 💥 Exploit | Ourgame.com GlworldOurgame.com Hangameplugincn18 Activex Control | 7/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited… | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Sejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control | 6/2/2008 | 16/6/2026 | Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | AOL YGP Piceditor Activex Control | 4/2/2008 | 16/6/2026 | Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5)… | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | Microsoft ActivexSejoong Namo Activesquare | 1/2/2008 | 16/6/2026 | The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | Comodo AntivirusMicrosoft Activex | 29/1/2008 | 16/6/2026 | A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method. | |
| Modificada | Alta (10) | 58% | 💥 Exploit | HP Virtual RoomsMicrosoft Activex | 23/1/2008 | 16/6/2026 | Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of… | |
| Modificada | Alta (9.3) | 11% | 💥 Exploit | Streamaudio Chaincast Proxymanager Activex Control | 12/1/2008 | 16/6/2026 | Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method. | |
| Modificada | Alta (10) | 29% | — | Microsoft VFP OLE Server Activex Control | 11/1/2008 | 16/6/2026 | The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method. |