Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

108 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)6.4%💥 ExploitLead Technologies Leadtools Isis Activex Control22/5/200716/6/2026
Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property.
ModificadaAlta (7.5)5.5%💥 ExploitPegasus Imagn Activex Control22/5/200716/6/2026
Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7)…
ModificadaAlta (9.4)4.6%💥 ExploitMorovia Barcode Activex Control13/5/200716/6/2026
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename.
ModificadaAlta (9.3)6.5%💥 ExploitBarcodewiz Barcode Activex Control10/5/200716/6/2026
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument.
ModificadaMedia (5)2.7%💥 ExploitTaltech TAL BAR Code Activex Control9/5/200716/6/2026
The SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to cause a denial of service (disk consumption) by uploading multiple bar codes, as demonstrated by a WSF package.
ModificadaAlta (9.3)4.1%—Taltech TAL BAR Code Activex Control9/5/200716/6/2026
Buffer overflow in the SaveBarCode function in the Taltech Tal Bar Code ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)7.2%💥 ExploitVersalsoft Http File Upload Activex Control9/5/200716/6/2026
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (7.5)7.6%—RIM Teamon Import Object Activex Control8/5/200716/6/2026
Buffer overflow in the SetLanguage function in Research In Motion (RIM) TeamOn Import Object ActiveX control (TOImport.dll) allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.8)38%💥 ExploitIncredimail Immenushellext Activex Control26/4/200716/6/2026
Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (9.3)7.1%—Gracenote Cddbcontrol Activex Control24/4/200716/6/2026
Multiple buffer overflows in the CDDBControl ActiveX control in Gracenote CDDB before 20070418 allow remote attackers to execute arbitrary code via long values for certain Proxy configuration parameters.
ModificadaMedia (6.8)3.1%—Microgaming Download Helper Activex Control24/4/200716/6/2026
Stack-based buffer overflow in the Microgaming Download Helper ActiveX control (dlhelper.dll) before 7.2.0.19, and the WebHandler Class control, allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (10)4.6%—Signkorea Skcommax Activex Control11/4/200716/6/2026
Multiple stack-based buffer overflows in the SignKorea SKCrypAX ActiveX control module 5.4.1.2 allow remote attackers to execute arbitrary code via a long string in unspecified arguments to the (1) DownloadCert, (2) DecryptFileByKey, and (3) EncryptFileByKey functions, a different module and vectors than…
ModificadaAlta (9.3)4.7%—Solidworks Sldimdownload Activex Control6/4/200716/6/2026
The Run function in SolidWorks sldimdownload ActiveX control in sldimdownload.dll before 16.0.0.6 allows remote attackers to execute arbitrary commands via the (1) installerpath and (2) applicationarguments arguments.
ModificadaAlta (10)3.4%—Signkorea Skcommax Activex Control28/3/200716/6/2026
Buffer overflow in the DownloadCertificateExt function in SignKorea SKCommAX ActiveX control module 7.2.0.2 and 3280 6.6.0.1 allows remote attackers to execute arbitrary code via a long pszUserID argument.
ModificadaMedia (6.8)4.3%💥 ExploitAlibaba Alipay Activex Control7/2/200716/6/2026
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScript function that invokes the Remove method with an invalid index argument, which is used as an offset for a function call.
ModificadaMedia (5)18%💥 ExploitCommon Controls Replacement Project Foldertreeview Activex ControlMicrosoft IE19/1/200716/6/2026
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long CCRP.RootFolder property value.
ModificadaAlta (7.5)7.9%💥 ExploitIconics Dialog Wrapper Module Activex Control31/12/200616/6/2026
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, and Vessel ActiveX, allows remote attackers to execute arbitrary code via a long (1) FileName or (2) Filter argument.
ModificadaAlta (9.3)15%💥 ExploitSKY Software Fileview Activex ControlWinzip21/11/200616/6/2026
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.
ModificadaAlta (7.6)2.3%—Studio Achtundachtzig Bloomooweb Activex Control3/11/200616/6/2026
BlooMooWeb ActiveX control (AidemATL.dll) allows remote attackers to (1) download arbitrary files via a URL in the bstrUrl parameter to the BW_DownloadFile method, (2) execute arbitrary local files via a file path in the bstrParams parameter to the BW_LaunchGame method, and (3) delete arbitrary files via a file path…
ModificadaAlta (7.5)4.5%—AOL YGP Screensaver Activex Control10/10/200616/6/2026
Buffer overflow in AOL You've Got Pictures (YGP) Screensaver ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)6.0%—AOL YGP PIC Downloader Activex Control10/10/200616/6/2026
Buffer overflow in AOL You've Got Pictures (YGP) Pic Downloader YGPPDownload ActiveX control (AOL.PicDownloadCtrl.1, YGPPicDownload.dll), as used in America Online 9.0 Security Edition, allows remote attackers to execute arbitrary code via a long argument to the SetAlbumName method.
ModificadaMedia (5)14%—Microsoft System Information Activex Control7/9/200616/6/2026
System Information ActiveX control (msinfo.dll), when accessed via Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via a SaveFile function with a long (1) computer and possibly (2) filename and (3) category argument.
ModificadaAlta (7.5)4.4%—Retro64 Cr64loader Activex Control6/9/200616/6/2026
Buffer overflow in the Retro64 / Miniclip CR64Loader ActiveX control allows remote attackers to execute arbitrary code via unspecified vectors involving an HTML document that references the CLSID of the control.
ModificadaAlta (7.5)1.3%—Touch Control Activex Control21/7/200616/6/2026
The Touch Control ActiveX control 2.0.0.55 allows remote attackers to read and possibly execute arbitrary files via a "file///" URI in the sPath parameter to the Execute function.
ModificadaAlta (7.5)3.2%—Webex Communications Webex Downloader Activex Control7/7/200616/6/2026
Multiple buffer overflows in WebEx Downloader ActiveX Control, possibly in versions before November 2005, allow remote attackers to execute arbitrary code via unspecified vectors.
Orbitaley — Vulnerabilidades