Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 78% | — | Microsoft Forefront Threat Management GatewayMicrosoft Internet Security AND Acceleration Server | 15/4/2009 | 16/6/2026 | The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a… | |
| Modificada | Alta (9.3) | 39% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft OfficeMicrosoft Office Powerpoint Viewer+5 | 11/9/2008 | 16/6/2026 | Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront… | |
| Modificada | Alta (9.3) | 37% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+10 | 11/9/2008 | 16/6/2026 | Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006,… | |
| Modificada | Alta (9.3) | 52% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+9 | 11/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9.3) | 31% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Alta (9.3) | 53% | — | Microsoft Digital Image SuiteMicrosoft Forefront Client SecurityMicrosoft Internet ExplorerMicrosoft Office+12 | 11/9/2008 | 16/6/2026 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438. | |
| Modificada | Alta (7.5) | 1.1% | — | Lagarde Storefront | 17/3/2008 | 16/6/2026 | SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 3.1% | — | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information. | |
| Modificada | Alta (7.5) | 3.5% | — | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username, (2) password, and (3) nickname fields in a "0x01" packet. | |
| Modificada | Alta (7.5) | 4.2% | — | Battlefront Dropteam | 8/10/2007 | 16/6/2026 | Multiple buffer overflows in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via (1) a crafted "0x5c" packet or (2) many 32-bit numbers in a "0x18" packet, or cause a denial of service (crash) via (3) a large "0x4b" packet. | |
| Modificada | Media (6.8) | 3.2% | — | Storefront FOR Gallery Storefront Gallery | 18/4/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter to (1) mods/business_functions.php or (2) mods/ui_functions.php. | |
| Modificada | Alta (9.3) | 30% | — | Microsoft AntigenMicrosoft Forefront SecurityMicrosoft Malware Protection EngineMicrosoft Windows Defender+1 | 13/2/2007 | 16/6/2026 | Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (5) | 2.6% | — | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Esmi Paypal Storefront | 2/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1) idpages parameter to pages.php or the (2) id2 parameter to products1.php. | |
| Modificada | Media (5) | 3.4% | — | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. | |
| Modificada | Media (5) | 3.1% | — | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory. | |
| Modificada | Media (4.3) | 2.2% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | deleteicon.aspx in AspDotNetStorefront 3.3 allows remote attackers to delete arbitrary product images via a modified ProductID parameter. | |
| Modificada | Alta (9) | 1.7% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executable extensions via admin/images.aspx. | |
| Modificada | Media (4.3) | 1.5% | — | Aspdotnetstorefront | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signin.aspx for AspDotNetStorefront 3.3 allows remote attackers to inject arbitrary web script or HTML via the returnurl parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Lagarde Storefront | 18/8/2003 | 16/6/2026 | SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to obtain sensitive user information via SQL statements in the password field. |