Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

97 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)78%—Microsoft Forefront Threat Management GatewayMicrosoft Internet Security AND Acceleration Server15/4/200916/6/2026
The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a…
ModificadaAlta (9.3)39%—Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft OfficeMicrosoft Office Powerpoint Viewer+511/9/200816/6/2026
Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront…
ModificadaAlta (9.3)37%—Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+1011/9/200816/6/2026
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006,…
ModificadaAlta (9.3)52%—Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+911/9/200816/6/2026
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000…
ModificadaAlta (9.3)31%—Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+1211/9/200816/6/2026
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000…
ModificadaAlta (9.3)53%—Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+1211/9/200816/6/2026
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000…
ModificadaMedia (5)13%—Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+513/5/200816/6/2026
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large…
ModificadaMedia (5)13%—Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+513/5/200816/6/2026
Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.
ModificadaAlta (7.5)1.1%—Lagarde Storefront17/3/200816/6/2026
SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)3.1%—Battlefront Dropteam8/10/200716/6/2026
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information.
ModificadaAlta (7.5)3.5%—Battlefront Dropteam8/10/200716/6/2026
Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username, (2) password, and (3) nickname fields in a "0x01" packet.
ModificadaAlta (7.5)4.2%—Battlefront Dropteam8/10/200716/6/2026
Multiple buffer overflows in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via (1) a crafted "0x5c" packet or (2) many 32-bit numbers in a "0x18" packet, or cause a denial of service (crash) via (3) a large "0x4b" packet.
ModificadaMedia (6.8)3.2%—Storefront FOR Gallery Storefront Gallery18/4/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php.
ModificadaAlta (9.3)30%—Microsoft AntigenMicrosoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender+113/2/200716/6/2026
Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file.
ModificadaMedia (5)2.6%—Esmi Paypal Storefront2/5/200516/6/2026
Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.5)1.3%—Esmi Paypal Storefront2/5/200516/6/2026
Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php.
ModificadaMedia (5)3.4%—Lucasarts Star Wars Battlefront10/1/200516/6/2026
Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname.
ModificadaMedia (5)3.1%—Lucasarts Star Wars Battlefront10/1/200516/6/2026
Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory.
ModificadaMedia (4.3)2.2%—Aspdotnetstorefront31/12/200416/6/2026
deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter.
ModificadaAlta (9)1.7%—Aspdotnetstorefront31/12/200416/6/2026
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx.
ModificadaMedia (4.3)1.5%—Aspdotnetstorefront31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter.
ModificadaAlta (7.5)1.0%—Lagarde Storefront18/8/200316/6/2026
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field.