Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)2.4%💥 ExploitYahoo Messenger10/7/200716/6/2026
Buffer overflow in Yahoo! Messenger 8.1 allows user-assisted remote authenticated users, who are listed in an address book, to execute arbitrary code via unspecified vectors, aka ZD-00000005. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not…
ModificadaAlta (7.8)1.6%—AOL Instant Messenger27/6/200716/6/2026
AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application crash) via a malformed header value in a SIP INVITE message, a different vulnerability than CVE-2007-3350.
ModificadaMedia (5)13%—Microsoft MSN Messenger27/6/200716/6/2026
Microsoft MSN Messenger 4.7 on Windows XP allows remote attackers to cause a denial of service (resource consumption) via a flood of SIP INVITE requests to the port specified for voice conversation.
ModificadaAlta (7.8)1.6%—AOL Instant Messenger22/6/200716/6/2026
AOL Instant Messenger (AIM) 6.1.32.1 on Windows XP allows remote attackers to cause a denial of service (application hang) via a flood of spoofed SIP INVITE requests.
ModificadaAlta (9.3)40%💥 ExploitYahoo Messenger11/6/200716/6/2026
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the send method. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)12%💥 ExploitYahoo Messenger11/6/200716/6/2026
Buffer overflow in the Yahoo! Webcam Viewer ActiveX control in ywcvwr.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows remote attackers to execute arbitrary code via a long server property value to the receive method.
ModificadaAlta (7.8)2.0%—Progress Webspeed Messenger30/4/200716/6/2026
Progress Webspeed Messenger allows remote attackers to obtain sensitive information via a WService parameter containing "wsbroker1/webutil/about.r", which reveals the operating system and product information.
ModificadaAlta (10)2.4%—Progress Webspeed Messenger25/4/200716/6/2026
Progress Webspeed Messenger allows remote attackers to read, create, modify, and execute arbitrary files by invoking webutil/_cpyfile.p in the WService parameter to (1) cgiip.exe or (2) wsisa.dll in scripts/, as demonstrated by using the save,editor options to create a new file using the fileName parameter.
ModificadaMedia (5)3.3%💥 ExploitAlvaros Messenger24/4/200716/6/2026
aMSN (aka Alvaro's Messenger) 0.96 and earlier allows remote attackers to cause a denial of service (application crash) by sending invalid data to TCP port 31337.
ModificadaMedia (4.3)3.7%—AOL ICQAOL Instant Messenger10/4/200716/6/2026
Directory traversal vulnerability in AOL Instant Messenger (AIM) 5.9 and earlier, and ICQ 5.1 and probably earlier, allows user-assisted remote attackers to write files to arbitrary locations via a .. (dot dot) in a filename in a file transfer operation.
ModificadaMedia (6.8)3.1%💥 ExploitPhp121 Instant Messenger10/4/200716/6/2026
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbitrary PHP code via a UNC share pathname or a local file pathname in the php121dir parameter, which is accessed by the file_exists function.
ModificadaAlta (9.3)8.4%—Yahoo Messenger6/4/200716/6/2026
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties.
ModificadaMedia (6)1.6%💥 ExploitV3 Chat V3chat Instant Messenger12/2/200716/6/2026
mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter.
ModificadaMedia (5)1.2%—Yahoo Messenger9/2/200716/6/2026
Unspecified vulnerability in the Chat Room functionality in Yahoo! Messenger 8.1.0.239 and earlier allows remote attackers to cause a denial of service via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (4.3)1.8%💥 ExploitYahoo Messenger6/2/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 and earlier allow user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG element to the (1) First Name, (2) Last Name, and (3)…
ModificadaBaja (3.5)1.4%—XMB Software U2U Instant Messenger26/1/200716/6/2026
Cross-site scripting (XSS) vulnerability in memcp.php in XMB U2U Instant Messenger allows remote authenticated users to inject arbitrary web script or HTML via the recipient field.
ModificadaMedia (6.4)1.5%—LAN Messenger26/12/200616/6/2026
Unspecified vulnerability in the info request mechanism in LAN Messenger before 1.5.1.2 allows remote attackers to cause a denial of service (application crash) or transmit spam via unspecified vectors.
ModificadaAlta (9.3)6.6%—Yahoo Messenger15/12/200616/6/2026
Buffer overflow in the YMMAPI.YMailAttach ActiveX control (ymmapi.dll) before 2005.1.1.4 in Yahoo! Messenger allows remote attackers to execute arbitrary code via a crafted HTML document. NOTE: some details were obtained from third party information.
ModificadaMedia (4.3)11%—Microsoft Windows Live Messenger4/12/200616/6/2026
Microsoft Windows Live Messenger 8.0 and earlier, when gestual emoticons are enabled, allows remote attackers to cause a denial of service (CPU consumption) via a long string composed of ":D" sequences, which are interpreted as emoticons.
ModificadaMedia (4.3)1.7%💥 ExploitSUN Iplanet Messaging Server Messenger Express3/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486,…
ModificadaMedia (4.3)4.8%💥 ExploitSUN Java System Messenger Express3/11/200616/6/2026
Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory…
ModificadaMedia (5)1.7%—Yahoo Messenger27/10/200616/6/2026
Unspecified vulnerability in Yahoo! Messenger (Service 18) before 8.1.0.195 allows remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted room name in a Conference Invite. NOTE: the provenance of this information is unknown; the details are obtained from third party…
ModificadaMedia (5)3.0%—Novell Groupwise Messenger5/10/200616/6/2026
Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to "zero-size strings in blowfish routines."
ModificadaBaja (2.6)1.2%—Yahoo Messenger25/9/200616/6/2026
Yahoo! Messenger for WAP permits saving messages that contain JavaScript, which allows user-assisted remote attackers to inject arbitrary web script or HTML via a URL at the online service.
ModificadaMedia (4.9)0.43%—Shape Services IM+ Mobile Instant Messenger7/9/200616/6/2026
Shape Services IM+ Mobile Instant Messenger for Pocket PC 3.10 stores usernames and passwords in plaintext in %PROGRAMFILES%\IMPlus\implus.cfg, which allows local users to obtain sensitive information by reading the file.
Orbitaley — Vulnerabilidades