Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2714▼ 164 respecto a la semana anterior
Críticas / altas1235▼ 317 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
1237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 1.5% | — | Kayako Liveresponse | 31/12/2005 | 16/6/2026 | Kayako liveResponse 2.x allows remote attackers to obtain sensitive information via a direct request to addressbook.php and other include scripts, which reveals the path in an error message. | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Kayako Liveresponse | 31/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in the calendar feature in Kayako liveResponse 2.x allow remote attackers to execute arbitrary SQL commands via the (1) year or (2) date parameter. | |
| Modificada | Alta (10) | 19% | — | Broadcom Brightstor Arcserve BackupBroadcom Brightstor Arcserve Backup Laptops DesktopsBroadcom Brightstor PortalBroadcom Brightstor Process Automation Manager+30 | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field. | |
| Modificada | Media (5.8) | 4.1% | 💥 Exploit | Kayako Liveresponse | 31/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Kayako liveResponse 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter or (2) name field when entering a session or sending a message. | |
| Modificada | Media (5) | 1.0% | — | Livejournal | 21/12/2005 | 16/6/2026 | cleanhtml.pl 1.129 in LiveJournal CVS before Dec 13 2005 allows remote attackers to inject scripting languages via the XSL namespace in XML, via vectors such as customview.cgi. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Livejournal | 21/12/2005 | 16/6/2026 | Validate-before-filter vulnerability in cleanhtml.pl 1.129 in LiveJournal CVS before Dec 7 2005, when the cleancss option is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks via a "\" (backslash) within a "javascript" scheme in a style property (such as "javas\cript"), which bypasses the… | |
| Modificada | Alta (7.8) | 1.7% | — | Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI | 29/11/2005 | 16/6/2026 | Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.5) | 3.3% | 💥 Exploit | Oliver MAY Athena PHP Website Administration | 29/11/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in athena.php in Oliver May Athena PHP Website Administration 0.1a allows remote attackers to execute arbitrary PHP code via a URL in the athena_dir parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Omnistar Interactive Omnistar Live | 26/11/2005 | 16/6/2026 | SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this identifier, but the correct identifier is CVE-2005-3240. | |
| Modificada | Alta (7.5) | 1.2% | — | Interspire Articlelive NX | 21/11/2005 | 16/6/2026 | SQL injection vulnerability in Interspire ArticleLive NX 0.3 allows remote attackers to execute arbitrary SQL commands via the Query parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Ubertec Help Center Live | 16/11/2005 | 16/6/2026 | PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability. | |
| Modificada | Baja (2.1) | 0.34% | — | Silc Secure Internet Live Conferencing | 7/9/2005 | 16/6/2026 | silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file. | |
| Modificada | Alta (7.5) | 4.0% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 30/8/2005 | 16/6/2026 | Stack-based buffer overflow in the ACE archive decompression library (vrAZace.dll) in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall, when compressed file scanning is enabled, allows remote attackers to execute arbitrary code via an ACE archive that contains a… | |
| Modificada | Alta (10) | 75% | 💥 Exploit | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors. | |
| Modificada | Media (5) | 3.5% | — | Hauri LivecallHauri Virobot Advanced ServerHauri Virobot ExpertHauri Virobot Linux Server | 23/8/2005 | 16/6/2026 | Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ, (3) CAB, (4) LZH, (5) RAR, (6) TAR and (7) ZIP files. | |
| Modificada | Media (5) | 3.1% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+20 | 23/8/2005 | 16/6/2026 | Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability." | |
| Modificada | Alta (10) | 7.3% | — | Broadcom Advantage Data TransportBroadcom AdviseitBroadcom Brightstor PortalBroadcom Brightstor SAN Manager+24 | 23/8/2005 | 16/6/2026 | Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets. | |
| Modificada | Media (5) | 9.1% | — | Microsoft Internet ExplorerMicrosoft Live Messenger | 19/7/2005 | 16/6/2026 | Microsoft MSN Messenger 9.0 e Internet Explorer 6.0 permiten que atacantes remotos causen una denegación de servicio (caída) mediante una imagen con un ICC Profile con un Tag Count grande. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Ubertec Help Center Live | 19/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Ubertec Help Center Live | 19/5/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php… | |
| Modificada | Media (6.5) | 2.9% | 💥 Exploit | Helpcenterlive Help Center Live | 19/5/2005 | 16/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Help Center Live allows remote attackers to perform actions as the administrator via a link or IMG tag to view.php. | |
| Modificada | Media (4.3) | 1.4% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ArticleLive 2005 allow remote attackers to inject arbitrary web script or HTML via the (1) Query, (2) Username, (3) LastName, (4) Biography, or (5) BlogId parameter. | |
| Modificada | Alta (7.5) | 1.9% | — | Interspire Articlelive | 11/5/2005 | 16/6/2026 | ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie. | |
| Modificada | Media (4.3) | 1.3% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 1.5% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message. |