Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.94% | — | Nestor Mata Cuthbert Taxonomy Navigator | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Litoweb Phpfilenavigator | 24/9/2011 | 16/6/2026 | PHPfileNavigator 2.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xestion/varios/logs.inc.php and certain other files. | |
| Modificada | Media (4.3) | 2.3% | — | Netscape Navigator | 20/7/2009 | 16/6/2026 | Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692. | |
| Modificada | Media (4) | 1.2% | — | Mozilla FirefoxMozilla GeckbMozilla SeamonkeyNetscape Navigator | 8/7/2008 | 16/6/2026 | Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain… | |
| Modificada | Media (4.3) | 1.0% | — | TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+6 | 22/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and… | |
| Modificada | Alta (7.5) | 10% | — | Microsoft Internet ExplorerNetscape Navigator | 27/7/2007 | 16/6/2026 | Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670. | |
| Modificada | Alta (9.3) | 14% | — | Microsoft Internet ExplorerNetscape Navigator | 21/7/2007 | 16/6/2026 | Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which… | |
| Modificada | Media (5) | 18% | 💥 Exploit | Adobe Acrobat ReaderMozilla FirefoxNetscape NavigatorOpera Browser | 10/3/2007 | 16/6/2026 | AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027… | |
| Modificada | Media (5) | 3.4% | — | Comscripts J-web Pics Navigator | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter. | |
| Modificada | Alta (7.8) | 2.8% | — | Jeunes-webmasters J-web Pics Navigator | 2/3/2007 | 16/6/2026 | Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter. | |
| Modificada | Media (5) | 2.0% | — | Mozilla FirefoxNetscape Navigator | 24/11/2006 | 16/6/2026 | The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows… | |
| Modificada | Alta (7.6) | 15% | 💥 Exploit | K-meleon Project K-meleonMozilla FirefoxNetscape Navigator | 21/8/2006 | 16/6/2026 | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency… | |
| Modificada | Media (4) | 9.8% | 💥 Exploit | Mozilla FirefoxMozilla SuiteMozilla SeamonkeyNetscape Navigator | 7/6/2006 | 16/6/2026 | Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the… | |
| Modificada | Media (4.3) | 1.7% | — | Mozilla FirefoxMozilla SuiteNetscape Navigator | 26/5/2006 | 16/6/2026 | Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message… | |
| Modificada | Media (5.1) | 2.6% | — | K-meleon Project K-meleonMozilla FirefoxNetscape Navigator | 20/4/2006 | 16/6/2026 | Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image… | |
| Modificada | Media (5) | 13% | 💥 Exploit | K-meleon Project K-meleonMozilla FirefoxMozilla SuiteNetscape Navigator | 9/12/2005 | 16/6/2026 | Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports,… | |
| Modificada | Alta (7.5) | 2.5% | — | Mozilla FirefoxMozillaNetscape Navigator | 2/5/2005 | 16/6/2026 | Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka… | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla FirefoxMozillaNetscape Navigator | 2/5/2005 | 16/6/2026 | Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1." | |
| Modificada | Media (5) | 10% | 💥 Exploit | Mozilla FirefoxMozillaNetscape Navigator | 2/5/2005 | 16/6/2026 | The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method. | |
| Modificada | Alta (7.5) | 1.7% | — | Netscape Navigator | 10/1/2005 | 16/6/2026 | Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | |
| Modificada | Alta (10) | 8.0% | — | Mozilla FirefoxMozillaMozilla ThunderbirdNetscape Navigator+6 | 31/12/2004 | 16/6/2026 | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows. | |
| Modificada | Baja (2.6) | 1.6% | — | Mozilla FirefoxMozillaNetscape Navigator | 31/12/2004 | 16/6/2026 | The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs. | |
| Modificada | Media (4.6) | 3.0% | — | Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+6 | 14/9/2004 | 16/6/2026 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | MozillaNetscape Navigator | 18/8/2004 | 16/6/2026 | Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 2.3% | 💥 Exploit | Netscape Navigator | 6/8/2004 | 16/6/2026 | Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack. |