Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 8.3% | 💥 Exploit | Microsoft Windows Live Messenger | 12/1/2010 | 16/6/2026 | A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session. | |
| Modificada | Media (4.3) | 5.1% | 💥 Exploit | Yahoo Messenger | 2/12/2009 | 16/6/2026 | An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument. | |
| Modificada | Alta (7.8) | 1.7% | — | Mitel Nupoint Messenger | 7/5/2009 | 16/6/2026 | The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Media (5) | 17% | — | Microsoft Windows Live Messenger | 19/2/2009 | 16/6/2026 | msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this… | |
| Modificada | Media (5) | 14% | — | Microsoft Windows Live Messenger | 2/1/2009 | 16/6/2026 | Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2) IPv4Internal-Addrs, and (3) IPv4Internal-Port header fields. | |
| Modificada | Media (5) | 16% | — | Microsoft Office Communications ServerMicrosoft Office CommunicatorMicrosoft Windows Live Messenger | 20/11/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet. | |
| Modificada | Alta (10) | 34% | — | Microsoft Windows Messenger | 13/8/2008 | 16/6/2026 | An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors. | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | Eyeball Networks Eyeball Messenger SDK | 31/7/2008 | 16/6/2026 | Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure… | |
| Modificada | Media (5) | 1.8% | — | Novell Groupwise Messenger | 13/6/2008 | 16/6/2026 | Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries. | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Novell Groupwise Messenger | 13/6/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name. | |
| Modificada | Alta (9.3) | 47% | 💥 Exploit | Icona Instant Messenger | 4/6/2008 | 16/6/2026 | The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run." | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Bigantsoft Bigant Messenger | 22/4/2008 | 16/6/2026 | Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 4.1% | — | Gadu-gadu Instant Messenger | 17/12/2007 | 16/6/2026 | Multiple buffer overflows in the HandleEmotsConfig function in the GG Client in Gadu-Gadu 7.7 Build 3669 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (gg.exe process crash) via a long string in an emots.txt file. | |
| Modificada | Media (4.3) | 0.43% | — | Gadu-gadu Instant Messenger | 17/12/2007 | 16/6/2026 | Gadu-Gadu does not properly perform protocol handling, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and add arbitrary user accounts or cause a denial of service as administrators via an unspecified "crafted link," possibly related to the gg protocol. | |
| Modificada | Media (4.3) | 0.97% | — | Gadu-gadu Instant Messenger | 17/12/2007 | 16/6/2026 | The gg protocol handler in Gadu-Gadu, when this product is installed but not running, does not properly handle the skin attribute, which allows remote attackers to cause a denial of service (resource consumption) via unspecified network traffic. | |
| Modificada | Media (4.3) | 17% | — | Microsoft Windows Live Messenger | 1/10/2007 | 16/6/2026 | Buffer overflow in the GDI engine in Windows Live Messenger, as used for Windows MSN Live 8.1, allows user-assisted remote attackers to cause a denial of service (application crash or system crash) and possibly execute arbitrary code by placing a malformed file in a new folder under the Sharing Folders path, and… | |
| Modificada | Media (6.8) | 1.9% | — | AOL Instant Messenger | 27/9/2007 | 16/6/2026 | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.5.3.12 and earlier allows remote attackers to execute arbitrary code via unspecified web script or HTML in an instant message, related to AIM's filtering of "specific tags and attributes" and the lack of Local Machine Zone lockdown. NOTE:… | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Yahoo Messenger | 20/9/2007 | 16/6/2026 | Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.1.0.421 allows remote attackers to force a download, and create or overwrite arbitrary files via a full pathname in the second argument to the GetFile method. | |
| Modificada | Media (5.8) | 2.8% | — | AOL AIM LiteAOL AIM PROAOL Instant Messenger | 14/9/2007 | 16/6/2026 | The embedded Internet Explorer server control in AOL Instant Messenger (AIM) 6.1.41.2 and 6.2.32.1, AIM Pro, and AIM Lite does not properly constrain the use of mshtml.dll's web script and HTML functionality for incoming instant messages, which allows remote attackers to place HTML into unexpected contexts or execute… | |
| Modificada | Alta (9.3) | 3.7% | 💥 Exploit | Telecom Italy Alice Messenger | 6/9/2007 | 16/6/2026 | The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to create registry keys and values via the arguments to the WriteRegistry method. | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | Yahoo Messenger | 31/8/2007 | 16/6/2026 | Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via certain file-transfer packets, possibly involving a buffer overflow, as demonstrated by ym8bug.exe. NOTE: this might be related to CVE-2007-4515. NOTE: the provenance of this information is unknown;… | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Yahoo Messenger | 31/8/2007 | 16/6/2026 | Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo! Messenger before 8.1.0.419 allows remote attackers to execute arbitrary code via unspecified vectors involving arguments to the (1) fvCom and (2) info methods. NOTE: some of these details are… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft MSN MessengerMicrosoft Windows Live Messenger | 31/8/2007 | 16/6/2026 | Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions. | |
| Modificada | Alta (9.3) | 9.3% | 💥 Exploit | Yahoo Messenger | 17/8/2007 | 16/6/2026 | Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denial of service (application crash) via a certain length field in JPEG2000 data, as demonstrated by sending an "invite to view my webcam" request, and then injecting a DLL into the attacker's peer… | |
| Modificada | Alta (7.6) | 5.7% | — | Yahoo Messenger | 21/7/2007 | 16/6/2026 | Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users to execute arbitrary code via a long e-mail address in an address book entry. NOTE: this might overlap CVE-2007-3638. |