Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

159 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies Pdf417 Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies Datamatrix Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies 1D Barcode Decoder Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (9)7.1%💥 ExploitMW6 Technologies Aztec Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (9.3)33%💥 ExploitDjvu Activex Control FOR Microsoft Office 20004/11/200816/6/2026
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.
ModificadaAlta (8.8)2.8%💥 ExploitVisagesoft Expert PDF Viewer Activex4/11/200816/6/2026
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.
ModificadaAlta (9.3)10%💥 ExploitDart Powertcp FTP FOR Activex22/10/200816/6/2026
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.
ModificadaAlta (9.3)8.7%💥 ExploitChilkat Software Chilkat XML Activex Control30/9/200816/6/2026
The Chilkat XML ChilkatUtil.CkData.1 ActiveX control (ChilkatUtil.dll) 3.0.3.0 and earlier allows remote attackers to create, overwrite, and modify arbitrary files for execution via a call to the (1) SaveToFile, (2) SaveToTempFile, or (3) AppendBinary method. NOTE: this issue might only be exploitable in limited…
ModificadaMedia (6.8)59%💥 ExploitMicrosoft Office Snapshot Viewer Activex7/7/200816/6/2026
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use…
ModificadaAlta (9.3)7.7%—Nctsoft Nctaudioeditor Activex Control29/5/200816/6/2026
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.8)6.0%—Alivemedia Alive MP3 WAV ConverterOnline Media Technologies Nctaudioeditor Activex ControlOnline Media Technologies Nctaudiostudio Activex ControlOrion Studios Cinematicmp3+229/5/200816/6/2026
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow…
ModificadaAlta (9.3)7.0%💥 ExploitChilkat Software Chilkathttp Activex2/4/200816/6/2026
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party…
ModificadaAlta (9.3)4.0%—Aurigma Image Uploader Activex ControlPiczo Imageuploader425/3/200816/6/2026
Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659.
ModificadaAlta (10)16%💥 ExploitSony Axruploadserver Activex ControlSony Imagestation13/2/200816/6/2026
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party…
ModificadaAlta (9.3)29%—Microsoft ActivexMicrosoft IEMicrosoft Internet Explorer12/2/200816/6/2026
Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."
ModificadaAlta (9.3)38%💥 ExploitAurigma Image Uploader Activex ControlFacebookFacebook Photouploader8/2/200816/6/2026
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.
ModificadaAlta (10)56%💥 ExploitAurigma Image Uploader Activex ControlMyspaceuploader8/2/200816/6/2026
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
ModificadaAlta (10)7.3%💥 ExploitOurgame.com GlworldOurgame.com Hangameplugincn18 Activex Control7/2/200816/6/2026
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited…
ModificadaAlta (7.5)4.6%💥 ExploitSejoong Namo ActivesquareSejoong Namo Namoinstall.1 Activex Control6/2/200816/6/2026
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.
ModificadaMedia (4.3)4.5%💥 ExploitAOL YGP Piceditor Activex Control4/2/200816/6/2026
Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5)…
ModificadaAlta (9.3)30%💥 ExploitMicrosoft ActivexSejoong Namo Activesquare1/2/200816/6/2026
The NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1 and earlier in Namo Web Editor in Sejoong Namo ActiveSquare 6 allows remote attackers to execute arbitrary code via a URL in the argument to the Install method. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)31%💥 ExploitComodo AntivirusMicrosoft Activex29/1/200816/6/2026
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.
ModificadaAlta (10)58%💥 ExploitHP Virtual RoomsMicrosoft Activex23/1/200816/6/2026
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as used in the installation process for HP Virtual Rooms, allow remote attackers to execute arbitrary code via a long (1) AuthenticationURL, (2) PortalAPIURL, or (3) cabroot property value. NOTE: some of…
ModificadaAlta (9.3)11%💥 ExploitStreamaudio Chaincast Proxymanager Activex Control12/1/200816/6/2026
Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.
ModificadaAlta (10)29%—Microsoft VFP OLE Server Activex Control11/1/200816/6/2026
The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.
Orbitaley — Vulnerabilidades