Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 111 respecto a la semana anterior
Críticas / altas1254▼ 280 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1236 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.3% | — | SUN Java System Content Delivery Server | 9/1/2007 | 16/6/2026 | Sun Java System Content Delivery Server 5.0 y 5.0 PU1 permite a atacantes remotos obtener información sensible sobre "detalles de contenido" a través de vectores no especificados. | |
| Modificada | Media (6.8) | 1.4% | — | PHP Live | 27/12/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en PHP Live! 3.2.2 y anteriores permiten a atacantes remotos inyectar secuencias de comandos web o HTML de su elección a través del parámetro (1) search_string de (a) setup/transcripts.php, el parámetro (2) l de (b) index.php, el campo (3)… | |
| Modificada | Media (4.3) | 0.34% | — | Symantec Livestate Agent FOR Windows | 6/12/2006 | 16/6/2026 | ** IMPUGNADA ** Symantec LiveState 7.1 Agent para Windows permite a usuarios locales obtener privilegios parando el proceso shstart.exe y abriendo "Web Self-Service" de la barra de iconos del sistema, lo cual abrirá una ventana de navegación ejecutándose con privilegios elevados. NOTA: varios investigadores de… | |
| Modificada | Media (4.3) | 11% | — | Microsoft Windows Live Messenger | 4/12/2006 | 16/6/2026 | Microsoft Windows Live Messenger 8.0 y versiones anteriores, cuando los emoticonos gestuales están habilitados, permite a atacantes remotos provocar una denegación de servicio (agotamiento de CPU) mediante una cadena larga compuesta de secuencias ":D", que son interpretadas como emoticonos. | |
| Modificada | Media (6.8) | 1.4% | — | Oliver | 22/11/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en loginform-inc.php de Oliver (anteriormente Webshare) 1.2.2 y anteriores, cuando register_globals está activado, permite a atacantes remotos ejecutar código PHP de su elección mediante un nombre de ruta UNC de recurso compartido o un nombre de ruta de archivo… | |
| Modificada | Alta (7.5) | 1.2% | — | ASP Scripter Easy PortalASP Scripter Live Support | 16/11/2006 | 16/6/2026 | Vulnerabilidad de inyección SQL en cpLogin.asp en ASP Scripter Easy Portal 1.4 y Live Support 1.3 permite a un atacante remotos ejecutar comandos SQL de su elección a través del parámetro Password. | |
| Modificada | Media (5) | 2.4% | — | SUN Java System Content Delivery Server | 25/8/2006 | 16/6/2026 | Vulnerabilidad no especificada en Sun Java System Content Delivery Server 4.0, 4.1, y 5.0 permite a atacantes locales y remotos leer datos de archivos de su elección a través de vectores no especificados. | |
| Modificada | Alta (7.5) | 8.3% | 💥 Exploit | Turnkey WEB Tools PHP Live Helper | 10/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión de fichero PHP remoto en global.php en Turnkey Web Tools PHP Live Helper 2.0 y anteriores permite a atacantes remotos ejecutar código PHP arbitrario mediante una URL en el parámetro abs_path. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | PHP Live | 28/7/2006 | 16/6/2026 | Vulnerabilidad PHP de inclusión remota de archivo en OSI Codes PHP Live! 3.2.1 y anteriores permite a atacantes remotos ejecutar código PHP de su elección a través de una URL en el parámetro css_path en (1) help.php y (2) setup/header.php. | |
| Modificada | Media (5.1) | 6.8% | — | Microsoft Windows Live Messenger | 27/6/2006 | 16/6/2026 | Desbordamiento de búfer basado en memoria dinámica (heap) en Windows Live Messenger v8.0, permite a atacantes asistidos por el usuario ejecutar código de su elección a través de un archivo de listas de contacto (.ctt) manipulado, lo que provoca un desbordamiento cuando el archivo es importado por el usuario. | |
| Modificada | Alta (7.5) | 4.7% | — | Livedata Iccp Server | 19/5/2006 | 16/6/2026 | Heap-based buffer overflow in the ISO Transport Service over TCP (RFC 1006) implementation of LiveData ICCP Server before 5.00.035 allows remote attackers to cause a denial of service or execute arbitrary code via malformed packets. | |
| Modificada | Media (5.8) | 1.3% | — | Turnkey WEB Tools PHP Live Helper | 16/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in chat.php in PHP Live Helper allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Ubertec Help Center Live | 26/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in the osTicket module in Help Center Live before 2.1.0 allow remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Media (4.6) | 2.1% | — | Adobe Livecycle Form Manager | 13/4/2006 | 16/6/2026 | Adobe LiveCycle Workflow 7.01 and LiveCycle Forum Manager 7.01 allows users to authenticate and perform privileged actions when their account is marked "OBSOLETE" but the account is also active, within the authentication system. | |
| Modificada | Alta (7.5) | 2.0% | — | Turnkey WEB Tools PHP Live Helper | 29/3/2006 | 16/6/2026 | Directory traversal vulnerability in (1) initiate.php and (2) possibly other PHP scripts in Turnkey Web Tools PHP Live Helper 1.8, and possibly later versions, allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie, as demonstrated by… | |
| Modificada | Alta (7.5) | 4.8% | — | Turnkey WEB Tools PHP Live Helper | 29/3/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Live Helper 1.8 allow remote attackers to include and execute arbitrary PHP code via the abs_path parameter in (1) initiate.php, (2) waiting.php, (3) welcome.php, (4) admin/index.php, (5) javascript.php, (6) checkchat.php, and (7) blank.php. | |
| Modificada | Media (4.3) | 1.3% | — | Xigla Absolute Live Support XE | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field. | |
| Modificada | Media (4.3) | 1.3% | — | PHP Live | 24/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in status_image.php in PHP Live! 3.0 allows remote attackers to inject arbitrary web script or HTML via the base_url parameter. | |
| Modificada | Media (4.3) | 1.4% | — | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages. | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Cynical Games Shoutlive | 1/3/2006 | 16/6/2026 | Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php. | |
| Modificada | Media (6.4) | 4.0% | 💥 Exploit | Pear Liveuser | 23/2/2006 | 16/6/2026 | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot… | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (5.8) | 4.1% | 💥 Exploit | Kayako Liveresponse | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message. | |
| Modificada | Media (6.4) | 1.5% | — | Kayako Liveresponse | 31/12/2005 | 16/6/2026 | Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message. |