Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 1.4% | — | SUN Java Virtual Machine | 11/10/2007 | 16/6/2026 | Interpretation conflict in the Sun Java Virtual Machine (JVM) allows user-assisted remote attackers to conduct a multi-pin DNS rebinding attack and execute arbitrary JavaScript in an intranet context, when an intranet web server has an HTML document that references a "mayscript=true" Java applet through a local… | |
| Modificada | Alta (10) | 6.3% | — | SUN Java 2 Micro EditionAISUN Kilobyte Virtual MachineAI | 31/12/2004 | 16/6/2026 | Java 2 Micro Edition (J2ME) does not properly validate bytecode, which allows remote attackers to escape the Kilobyte Virtual Machine (KVM) sandbox and execute arbitrary code. | |
| Modificada | Media (6.4) | 13% | — | Microsoft Java Virtual Machine | 27/7/2004 | 16/6/2026 | Microsoft Java virtual machine (VM) 5.0.0.3810 allows remote attackers to bypass sandbox restrictions to read or write certain data between applets from different domains via the "GET/Key" and "PUT/Key/Value" commands, aka "cross-site Java." | |
| Modificada | Alta (7.5) | 37% | — | Microsoft Virtual MachineMicrosoft Windows 2000Microsoft Windows 2000 Terminal Services | 5/5/2003 | 16/6/2026 | The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise." | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, provides a public load0() method for the CabCracker class (com.ms.vm.loader.CabCracker), which allows remote attackers to bypass the security checks that are performed by the load() method. | |
| Modificada | Media (5) | 18% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read arbitrary local files and network shares via an applet tag with a codebase set to a "file://%00" (null character) URL. | |
| Modificada | Media (5) | 20% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | Stack-based buffer overflow in the Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service via a long class name through (1) Class.forName or (2) ClassLoader.loadClass. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, can provide HTML object references to applets via Javascript, which allows remote attackers to cause a denial of service (crash due to illegal memory accesses) and possibly conduct other unauthorized activities via an applet that uses those references to… | |
| Modificada | Alta (7.5) | 21% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to steal cookies and execute script in a different security context via a URL that contains a colon in the domain portion, which is not properly parsed and loads an applet from a malicious site within the security context of the… | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to cause a denial of service (crash) and possibly conduct other unauthorized activities via applet tags in HTML that bypass Java class restrictions (such as private constructors) by providing the class name in the code parameter,… | |
| Modificada | Media (5) | 17% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to determine the current directory of the Internet Explorer process via the getAbsolutePath() method in a File() call. | |
| Modificada | Alta (7.5) | 22% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java virtual machine (VM) build 5.0.3805 and earlier, as used in Internet Explorer, allows remote attackers to extend the Standard Security Manager (SSM) class (com.ms.security.StandardSecurityManager) and bypass intended StandardSecurityManager restrictions by modifying the (1) deniedDefinitionPackages… | |
| Modificada | Media (6.4) | 14% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read and modify the contents of the Clipboard via an applet that accesses the (1) ClipBoardGetText and (2) ClipBoardSetText methods of the INativeServices class. | |
| Modificada | Alta (7.5) | 16% | — | Microsoft Java Virtual Machine | 29/11/2002 | 16/6/2026 | The Microsoft Java implementation, as used in Internet Explorer, allows remote attackers to read restricted process memory, cause a denial of service (crash), and possibly execute arbitrary code via the getNativeServices function, which creates an instance of the com.ms.awt.peer.INativeServices (INativeServices)… | |
| Modificada | Media (5) | 27% | — | Microsoft Virtual Machine | 11/10/2002 | 16/6/2026 | Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw." | |
| Modificada | Alta (7.5) | 20% | — | Microsoft Virtual Machine | 11/10/2002 | 16/6/2026 | A certain class that supports XML (Extensible Markup Language) in Microsoft Virtual Machine (VM) 5.0.3805 and earlier, probably com.ms.osp.ospmrshl, exposes certain unsafe methods, which allows remote attackers to execute unsafe code via a Java applet, aka "Inappropriate Methods Exposed in XML Support Classes." | |
| Modificada | Alta (7.5) | 41% | — | Microsoft Virtual Machine | 11/10/2002 | 16/6/2026 | Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL… | |
| Modificada | Alta (7.5) | 6.5% | — | Microsoft Virtual Machine | 24/9/2002 | 16/6/2026 | The Java logging feature for the Java Virtual Machine in Internet Explorer writes output from functions such as System.out.println to a known pathname, which can be used to execute arbitrary code. | |
| Modificada | Alta (7.5) | 27% | — | HP Java Jre-jdkMicrosoft Virtual MachineSUN JDKSUN JRE+1 | 19/3/2002 | 16/6/2026 | Java Runtime Environment (JRE) Bytecode Verifier allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, as seen in (1) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, (2) Netscape 6.2.1 and earlier, and possibly other… | |
| Modificada | Media (5) | 8.6% | — | Microsoft Virtual MachineSUN JDKSUN JRESUN SDK | 15/3/2002 | 16/6/2026 | Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and… | |
| Modificada | Alta (7.5) | 34% | — | Microsoft Virtual MachineNetscape Communicator | 20/10/2000 | 16/6/2026 | Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackers to create a server on the victim's system via a malicious applet, as demonstrated by Brown Orifice. | |
| Modificada | Baja (2.6) | 19% | — | Microsoft Virtual Machine | 31/1/2000 | 16/6/2026 | Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function. | |
| Modificada | Alta (9.3) | 7.2% | — | Microsoft Java Virtual Machine | 21/10/1999 | 16/6/2026 | The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment. | |
| Modificada | Alta (7.6) | 12% | — | Microsoft Virtual Machine | 21/10/1999 | 16/6/2026 | Microsoft Virtual Machine (VM) allows remote attackers to escape the Java sandbox and execute commands via an applet containing an illegal cast operation, aka the "Virtual Machine Verifier" vulnerability. |