Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

150 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.94%—Nestor Mata Cuthbert Taxonomy Navigator20/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Taxonomy Navigator module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.2%—Litoweb Phpfilenavigator24/9/201116/6/2026
PHPfileNavigator 2.3.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xestion/varios/logs.inc.php and certain other files.
ModificadaMedia (4.3)2.3%—Netscape Navigator20/7/200916/6/2026
Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.
ModificadaMedia (4)1.2%—Mozilla FirefoxMozilla GeckbMozilla SeamonkeyNetscape Navigator8/7/200816/6/2026
Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain…
ModificadaMedia (4.3)1.0%—TOR World COM VoteTOR World I-navigatorTOR World Interactive BBSTOR World Mobile Frontier+622/2/200816/6/2026
Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and…
ModificadaAlta (7.5)10%—Microsoft Internet ExplorerNetscape Navigator27/7/200716/6/2026
Multiple argument injection vulnerabilities in Netscape Navigator 9 allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI, a similar issue to CVE-2007-3670.
ModificadaAlta (9.3)14%—Microsoft Internet ExplorerNetscape Navigator21/7/200716/6/2026
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a -chrome argument to the navigatorurl URI, which…
ModificadaMedia (5)18%💥 ExploitAdobe Acrobat ReaderMozilla FirefoxNetscape NavigatorOpera Browser10/3/200716/6/2026
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027…
ModificadaMedia (5)3.4%—Comscripts J-web Pics Navigator2/3/200716/6/2026
Directory traversal vulnerability in jwpn-photos.php in J-Web Pics Navigator 2.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.
ModificadaAlta (7.8)2.8%—Jeunes-webmasters J-web Pics Navigator2/3/200716/6/2026
Directory traversal vulnerability in pn-menu.php in J-Web Pics Navigator 1.0 allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter.
ModificadaMedia (5)2.0%—Mozilla FirefoxNetscape Navigator24/11/200616/6/2026
The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows…
ModificadaAlta (7.6)15%💥 ExploitK-meleon Project K-meleonMozilla FirefoxNetscape Navigator21/8/200616/6/2026
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency…
ModificadaMedia (4)9.8%💥 ExploitMozilla FirefoxMozilla SuiteMozilla SeamonkeyNetscape Navigator7/6/200616/6/2026
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the…
ModificadaMedia (4.3)1.7%—Mozilla FirefoxMozilla SuiteNetscape Navigator26/5/200616/6/2026
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message…
ModificadaMedia (5.1)2.6%—K-meleon Project K-meleonMozilla FirefoxNetscape Navigator20/4/200616/6/2026
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image…
ModificadaMedia (5)13%💥 ExploitK-meleon Project K-meleonMozilla FirefoxMozilla SuiteNetscape Navigator9/12/200516/6/2026
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports,…
ModificadaAlta (7.5)2.5%—Mozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka…
ModificadaAlta (7.5)2.3%—Mozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."
ModificadaMedia (5)10%💥 ExploitMozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
ModificadaAlta (7.5)1.7%—Netscape Navigator10/1/200516/6/2026
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
ModificadaAlta (10)8.0%—Mozilla FirefoxMozillaMozilla ThunderbirdNetscape Navigator+631/12/200416/6/2026
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
ModificadaBaja (2.6)1.6%—Mozilla FirefoxMozillaNetscape Navigator31/12/200416/6/2026
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.
ModificadaMedia (4.6)3.0%—Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+614/9/200416/6/2026
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
ModificadaAlta (10)13%💥 ExploitMozillaNetscape Navigator18/8/200416/6/2026
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.
ModificadaMedia (5)2.3%💥 ExploitNetscape Navigator6/8/200416/6/2026
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
Orbitaley — Vulnerabilidades