Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

1144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.1%—Digi-net Technologies Digichat31/12/200216/6/2026
Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet.
ModificadaMedia (5)2.5%—Parachat Server31/12/200216/6/2026
ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users.
ModificadaAlta (7.5)1.1%—Webchat.org WebchatXoops31/12/200216/6/2026
SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.
ModificadaMedia (5)5.8%💥 ExploitMelange Chat System24/12/200216/6/2026
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and possibly execute arbitrary code via the msgText buffer in the chat_InterpretData function, as demonstrated via a long Nick (nickname) request.
ModificadaMedia (5)1.5%—Arsc Really Simple Chat12/8/200216/6/2026
home.php in ARSC (Really Simple Chat) 1.0.1 and earlier allows remote attackers to determine the full pathname of the web server via an invalid language in the arsc_language parameter, which leaks the pathname in an error message.
ModificadaAlta (7.5)8.6%💥 ExploitMelange Chat System3/7/200216/6/2026
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long argument in the /yell command, (2) long lines in the /etc/melange.conf configuration file, (3) long file names, or possibly other attacks.
ModificadaAlta (7.5)8.1%💥 ExploitXchat25/6/200216/6/2026
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitrary IRC commands as other clients via encoded characters in a PRIVMSG command that calls CTCP PING, which expands the characters in the client response when the percascii variable is set.
ModificadaAlta (7.5)2.4%—Xchat25/6/200216/6/2026
XChat IRC client allows remote attackers to execute arbitrary commands via a /dns command on a host whose DNS reverse lookup contains shell metacharacters.
ModificadaAlta (7.5)24%—Microsoft MSN Chat ControlMicrosoft MSN MessengerMicrosoft MSN Messenger Service FOR Exchange29/5/200216/6/2026
Desbordamiento de búfer en el control ActiveX Microsoft MSN Chat, usado en MSN Messenger 4.5 y 4.6, y Exchange Instant Messenger 4.5 y 4.6, permite a atacantes remotos ejecutar código arbitrario mediante un parámetro ResDLL largo en el OCX MSNChat.
ModificadaAlta (7.5)2.8%—Xchat18/10/200116/6/2026
Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.
ModificadaMedia (5)7.1%💥 ExploitSpytech Spynet Chat22/8/200116/6/2026
Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of connections to port 6387.
ModificadaMedia (5)7.1%💥 ExploitFaust Informatics Freestyle Chat14/8/200116/6/2026
Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (e.g., GET /aux HTTP/1.0).
ModificadaMedia (5)3.7%💥 ExploitFaust Informatics Freestyle Chat14/8/200116/6/2026
Directory traversal vulnerability in Faust Informatics Freestyle Chat server prior to 4.1 SR3 allows a remote attacker to read arbitrary files via a specially crafted URL which includes variations of a '..' (dot dot) attack such as '...' or '....'.
ModificadaAlta (7.5)1.1%—Phpheaven Phpmychat7/2/200116/6/2026
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.
ModificadaAlta (7.2)0.68%—Phpheaven Phpmychat7/2/200116/6/2026
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.
ModificadaMedia (4.6)0.34%—Volano LLC Volanochatpro9/1/200116/6/2026
The installation of VolanoChatPro chat server sets world-readable permissions for its configuration file and stores the server administrator passwords in plaintext, which allows local users to gain privileges on the server.
ModificadaAlta (7.5)9.2%💥 ExploitXchat20/10/200016/6/2026
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell metacharacters into a URL which XChat uses to launch a web browser.
ModificadaMedia (5)3.1%💥 ExploitLeafdigital Leafchat25/6/200016/6/2026
LeafChat 1.7 IRC client allows a remote IRC server to cause a denial of service by rapidly sending a large amount of error messages.
ModificadaMedia (5)1.3%—Apple Ichat Server9/9/199816/6/2026
iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.