Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
117 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Mercuryboard Message Board | 13/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained… | |
| Modificada | Media (6) | 3.6% | 💥 Exploit | David Harris Mercury 32 | 20/9/2007 | 16/6/2026 | Stack-based buffer overflow in IMAPD in Mercury/32 4.52 allows remote authenticated users to execute arbitrary code via a long argument in a SEARCH ON command. NOTE: this issue might overlap with CVE-2004-1211. | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | Pmail Mercury Mail Transport System | 21/8/2007 | 16/6/2026 | Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961. | |
| Modificada | Media (6.5) | 6.1% | 💥 Exploit | HP Mercury Quality Center | 6/4/2007 | 16/6/2026 | qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authenticated users to execute arbitrary SQL commands via the RunQuery method. | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | HP Mercury Quality Center | 2/4/2007 | 16/6/2026 | Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for Mercury Quality Center 9.0 before Patch 12.1, and 8.2 SP1 before Patch 32, allows remote attackers to execute arbitrary code via a long ProgColor property. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Atrium Software Mercur Imapd | 21/3/2007 | 16/6/2026 | Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, allow remote attackers to execute arbitrary code via a long NTLMSSP argument that triggers a stack-based buffer overflow. | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Atrium Software Mercur ImapdAtrium Software Mercur Messaging 2005 | 21/3/2007 | 16/6/2026 | Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSCRIBE command. | |
| Modificada | Alta (10) | 60% | 💥 Exploit | Pmail Mercury Mail Transport System | 10/3/2007 | 16/6/2026 | Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the same issue as CVE-2006-5961. | |
| Modificada | Alta (7.8) | 2.0% | — | Atrium Software Mercur Messaging 2005 | 23/2/2007 | 16/6/2026 | Multiple buffer overflows in MERCUR Messaging 2005 before Service Pack 4 allow remote attackers to cause a denial of service (crash) via (1) "long command lines at port 32000" and (2) certain name service queries that are not properly handled by the SMTP service. | |
| Modificada | Media (5) | 1.5% | — | Atrium Software Mercur Messaging 2005 | 23/2/2007 | 16/6/2026 | The IMAP4 service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a message with a long subject field. | |
| Modificada | Alta (7.8) | 1.8% | — | Atrium Software Mercur Messaging 2005 | 23/2/2007 | 16/6/2026 | Unspecified vulnerability in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (crash) via a TOP command to the POP3 service. | |
| Modificada | Alta (7.8) | 1.8% | — | Atrium Software Mercur Messaging 2005 | 23/2/2007 | 16/6/2026 | The SMTP service in MERCUR Messaging 2005 before Service Pack 4 allows remote attackers to cause a denial of service (infinite loop) via a message in which neither the originator nor recipient address is known. | |
| Modificada | Alta (10) | 45% | — | HP Mercury Loadrunner AgentHP Mercury Monitor Over FirewallHP Mercury Performance Center Agent | 8/2/2007 | 16/6/2026 | Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in… | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Pegasus Mercury Mail Transport System | 17/11/2006 | 16/6/2026 | Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally reported in a GLEG VulnDisco pack. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The original researcher is reliable. | |
| Modificada | Media (4.9) | 1.2% | — | HP Mercury Sitescope | 3/10/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Mercury SiteScope 8.2 (8.1.2.0) allow remote authenticated users to inject arbitrary web script or HTML via (1) "any field create name field" except "create new group name" or (2) any description field. | |
| Modificada | Media (4) | 1.5% | — | HP Mercury Sitescope | 3/10/2006 | 16/6/2026 | Mercury SiteScope 8.2 (8.1.2.0) allows remote authenticated users to cause a denial of service (loss of connectivity to the classic interface) via attempted HTML injection into the "new monitor description" field. | |
| Modificada | Baja (2.1) | 0.33% | — | Mercury Messenger | 18/7/2006 | 16/6/2026 | Mercury Messenger, possibly 1.7.1.1 and other versions, when running on a multi-user Mac OS X platform, stores chat logs with world-readable permissions within the /Users directory, which allows local users to read the chat logs from other users. | |
| Modificada | Alta (10) | 69% | 💥 Exploit | Mercur Messaging | 19/3/2006 | 16/6/2026 | Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different… | |
| Modificada | Media (4.3) | 0.94% | — | TMC Visionpool Mercury CMS | 20/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) content and (2) criteria parameters. | |
| Modificada | Alta (7.5) | 1.2% | — | TMC Visionpool Mercury CMS | 20/12/2005 | 16/6/2026 | SQL injection vulnerability in index.cfm in Mercury CMS 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (7.5) | 65% | 💥 Exploit | David Harris Mercury Mail Transport System | 20/12/2005 | 16/6/2026 | Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Mercuryboard Message Board | 21/6/2005 | 16/6/2026 | SQL injection vulnerability in index.php for MercuryBoard 1.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header. | |
| Modificada | Alta (7.5) | 1.9% | — | Mercur Messaging | 18/5/2005 | 16/6/2026 | Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) deletemessage.ctml, (3) origmessage.ctml, or (4) readmessage.ctml, the Message.Id parameter to editmessage.ctml, or the (5)… | |
| Modificada | Media (5) | 1.3% | — | Mercur Messaging | 18/5/2005 | 16/6/2026 | Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space ("%20"). | |
| Modificada | Media (4.3) | 0.94% | — | Mercuryboard | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field. |