Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | Digi-net Technologies Digichat | 31/12/2002 | 16/6/2026 | Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet. | |
| Modificada | Media (5) | 2.5% | — | Parachat Server | 31/12/2002 | 16/6/2026 | ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users. | |
| Modificada | Alta (7.5) | 1.1% | — | Webchat.org WebchatXoops | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter. | |
| Modificada | Media (5) | 5.8% | 💥 Exploit | Melange Chat System | 24/12/2002 | 16/6/2026 | Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request. | |
| Modificada | Media (5) | 1.5% | — | Arsc Really Simple Chat | 12/8/2002 | 16/6/2026 | home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Melange Chat System | 3/7/2002 | 16/6/2026 | Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Xchat | 25/6/2002 | 16/6/2026 | XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the percascii variable is set. | |
| Modificada | Alta (7.5) | 2.4% | — | Xchat | 25/6/2002 | 16/6/2026 | XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metacharacters. | |
| Modificada | Alta (7.5) | 24% | — | Microsoft MSN Chat ControlMicrosoft MSN MessengerMicrosoft MSN Messenger Service FOR Exchange | 29/5/2002 | 16/6/2026 | Desbordamiento de búfer en el control ActiveX Microsoft MSN Chat, usado en MSN Messenger 4.5 y 4.6, y Exchange Instant Messenger 4.5 y 4.6, permite a atacantes remotos ejecutar código arbitrario mediante un parámetro ResDLL largo en el OCX MSNChat. | |
| Modificada | Alta (7.5) | 2.8% | — | Xchat | 18/10/2001 | 16/6/2026 | Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Spytech Spynet Chat | 22/8/2001 | 16/6/2026 | Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387. | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Faust Informatics Freestyle Chat | 14/8/2001 | 16/6/2026 | Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0). | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Faust Informatics Freestyle Chat | 14/8/2001 | 16/6/2026 | Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpheaven Phpmychat | 7/2/2001 | 16/6/2026 | Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables. | |
| Modificada | Alta (7.2) | 0.68% | — | Phpheaven Phpmychat | 7/2/2001 | 16/6/2026 | Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter. | |
| Modificada | Media (4.6) | 0.34% | — | Volano LLC Volanochatpro | 9/1/2001 | 16/6/2026 | The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server. | |
| Modificada | Alta (7.5) | 9.2% | 💥 Exploit | Xchat | 20/10/2000 | 16/6/2026 | IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Leafdigital Leafchat | 25/6/2000 | 16/6/2026 | LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages. | |
| Modificada | Media (5) | 1.3% | — | Apple Ichat Server | 9/9/1998 | 16/6/2026 | iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. |