Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
159 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Gateway Cweblaunchctl Activex ControlGateway Weblaunch | 10/1/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are… | |
| Modificada | Media (6.8) | 3.7% | 💥 Exploit | Ravware Flic Activex Control | 21/12/2007 | 16/6/2026 | Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arbitrary code via a long FileName property. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Intuit BookkeepingIntuit ProseriesIntuit QuickbooksIntuit Quicken+4 | 15/12/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Vantage Linguistics AnswerWorks, and Intuit Clearly Bookkeeping, ProSeries, QuickBooks, Quicken, QuickTax, and TurboTax, allow remote attackers to execute arbitrary code via long arguments to the (1)… | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Webex Communications Webex Gpccontainer Activex Control | 15/11/2007 | 16/6/2026 | Unspecified vulnerability in the GpcContainer.GpcContainer.1 ActiveX control in WebEx allows remote attackers to cause a denial of service (memory access violation and crash) via (1) an invalid argument to the InitParam method or (2) an unspecified vector involving the SetParam method. | |
| Modificada | Alta (9.3) | 3.7% | 💥 Exploit | Edraw Flowchart Activex | 5/11/2007 | 16/6/2026 | Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote attackers to create or overwrite arbitrary files with arbitrary contents via a full pathname in the second argument to the HttpDownloadFile method, a different product than CVE-2007-4420. | |
| Modificada | Alta (7.5) | 4.7% | — | Automated Solutions Modbus Slave Activex Control | 19/9/2007 | 16/6/2026 | Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | MW6 Technologies Qrcode Activex | 19/9/2007 | 16/6/2026 | Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Technologies QRCode ActiveX 3.0.0.1 and earlier allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveAsBMP or (2) SaveAsWMF method. NOTE: some… | |
| Modificada | Alta (9.3) | 6.7% | — | Photochannel PNI Digital Media Upload Plugin Activex Control | 18/9/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (9.3) | 7.0% | 💥 Exploit | Clever Components Internet Activex Suite | 30/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Internet ActiveX Suite 6.2 allows remote attackers to create or overwrite arbitrary files via a full pathname in the second argument to the GetToFile method. NOTE: some of these details are obtained from… | |
| Modificada | Media (6.8) | 4.6% | 💥 Exploit | HP Photo Digital Imaging Activex Control | 10/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in a certain ActiveX control in hpqvwocx.dll 2.1.0.556 in Hewlett-Packard (HP) Digital Imaging allows remote attackers to create or overwrite arbitrary files via the second argument to the SaveToFile method. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | Chilkat Software Chilkat ZIP Activex Control | 10/7/2007 | 16/6/2026 | Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) SaveLastError method and probably the (2) WriteExe method. | |
| Modificada | Alta (7.6) | 14% | 💥 Exploit | AMX Netlinx VNC Activex Control | 3/7/2007 | 16/6/2026 | Multiple buffer overflows in the AMX NetLinx VNC (AmxVnc) ActiveX control in AmxVnc.dll 1.0.13.0 allow remote attackers to execute arbitrary code via long (1) Host, (2) Password, or (3) LogFile property values. | |
| Modificada | Media (6.4) | 8.8% | 💥 Exploit | HP Photo Digital Imaging Activex Control | 29/6/2007 | 16/6/2026 | Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imaging allows remote attackers to create or overwrite arbitrary files via the argument to the saveXMLAsFile method. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | Civiltech Avax Vector Activex | 27/6/2007 | 16/6/2026 | A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the WriteMovie method. | |
| Modificada | Alta (9.3) | 35% | 💥 Exploit | RKD Software Barcode Activex | 27/6/2007 | 16/6/2026 | Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (7.8) | 42% | 💥 Exploit | Microsoft OfficeMicrosoft Office Msodatasourcecontrol Activex | 19/6/2007 | 16/6/2026 | Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method. | |
| Modificada | Alta (9.3) | 6.5% | — | Zoomify Viewer Activex Control | 11/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Zoomify Viewer ActiveX control in ZActiveX.dll might allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 44% | 💥 Exploit | Microsoft Internet ExplorerProvideo Camimage Activex Control | 7/6/2007 | 16/6/2026 | Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value. | |
| Modificada | Media (6.8) | 3.4% | — | Media Technology Group Cdpass Activex Control | 1/6/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Media Technology Group CDPass ActiveX control in CDPass.dll allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the GetTOC2 method. | |
| Modificada | Alta (9.3) | 5.2% | — | BT Business Connect Webhelper Activex Control | 1/6/2007 | 16/6/2026 | Multiple buffer overflows in the British Telecommunications Business Connect webhelper ActiveX control before 1.0.0.7 in btbconnectwebcontrol.dll allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 4.7% | 💥 Exploit | H+H Vcdapilibapi Activex ControlH+H Virtual CD | 24/5/2007 | 16/6/2026 | The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitrary commands via a command line in the first argument to the VCDLaunchAndWait function. | |
| Modificada | Alta (10) | 4.6% | — | SKY Software Shcombobox Activex ControlSKY Software Shell Megapack Activex | 24/5/2007 | 16/6/2026 | Stack-based buffer overflow in the SetPath function in the shComboBox ActiveX control (shcmb80.ocx) in Sky Software Shell MegaPack ActiveX 8.0 allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (9.3) | 6.4% | 💥 Exploit | Lead Technologies Leadtools Isis Activex Control | 22/5/2007 | 16/6/2026 | Heap-based buffer overflow in LEAD Technologies LEADTOOLS ISIS ActiveX Control (ltisi14E.ocx) 14.5.0.44 and earlier allows remote attackers to execute arbitrary code via a long DriverName property. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Pegasus Imagn Activex Control | 22/5/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the Pegasus ImagN' ActiveX control (IMW32O40.OCX) 4.00.041 allow remote attackers to execute arbitrary code via (1) a long FileName parameter, or unspecified vectors involving the (2) BeginReport, (3) CreatePictureExA, (4) DefineImage, (5) DefineImageEx, (6) DefineImageFox, (7)… | |
| Modificada | Alta (9.4) | 4.6% | 💥 Exploit | Morovia Barcode Activex Control | 13/5/2007 | 16/6/2026 | A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrary files by calling the Save method with an arbitrary filename. |