Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

203 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.1%—EMC CenterstageEMC Documentum Foundation ServicesEMC MY Documentum FOR DesktopEMC MY Documentum FOR Microsoft Outlook8/7/201417/6/2026
The JAXB XML parser in EMC Documentum Foundation Services (DFS) 6.6 before P39, 6.7 SP1 before P28, and 6.7 SP2 before P15, as used in My Documentum for Desktop, My Documentum for Microsoft Outlook, and CenterStage, allows remote authenticated users to read arbitrary files via an external entity declaration in…
ModificadaMedia (5)11%—Microsoft Outlook13/11/201316/6/2026
Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."
ModificadaAlta (9.3)19%—Microsoft Outlook11/9/201316/6/2026
Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."
ModificadaAlta (10)1.4%—Mobisynapse Moffice-outlook Sync7/3/201216/6/2026
Unspecified vulnerability in the mOffice - Outlook sync (com.innov8tion.isharesync) application 3.1 for Android has unknown impact and attack vectors.
ModificadaAlta (9.3)17%—Microsoft Outlook15/9/201016/6/2026
Heap-based buffer overflow in Microsoft Outlook 2002 SP3, 2003 SP3, and 2007 SP2, when Online Mode for an Exchange Server is enabled, allows remote attackers to execute arbitrary code via a crafted e-mail message, aka "Heap Based Buffer Overflow in Outlook Vulnerability."
ModificadaMedia (6.8)8.4%💥 ExploitMicrosoft Outlook WEB Access7/9/201016/6/2026
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.
ModificadaAlta (9.3)19%💥 ExploitMicrosoft Outlook ExpressMicrosoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2003+327/8/201016/6/2026
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current…
ModificadaAlta (9.3)55%💥 ExploitMicrosoft Outlook15/7/201016/6/2026
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
ModificadaMedia (5)1.1%—Cisco Ironport Desktop Flag Plugin FOR Outlook14/5/201016/6/2026
The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intended to be encrypted, aka bug 65623.
ModificadaAlta (9.3)20%💥 ExploitMicrosoft Outlook ExpressMicrosoft Windows Live MailMicrosoft Windows Mail12/5/201016/6/2026
Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows…
ModificadaMedia (4.3)12%—Microsoft Outlook Express11/12/200816/6/2026
The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service…
ModificadaAlta (9.3)37%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; and Microsoft Works 8 allow remote attackers to execute arbitrary code via a crafted Word…
ModificadaAlta (9.3)23%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers…
ModificadaAlta (9.3)23%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1 allow remote attackers to execute arbitrary code via crafted control words in (1) an RTF file…
ModificadaAlta (9.3)38%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers…
ModificadaAlta (9.3)34%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; and Office 2004 for Mac allow remote attackers to execute arbitrary…
ModificadaAlta (9.3)23%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code…
ModificadaAlta (9.3)33%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac…
ModificadaAlta (9.3)29%—Microsoft OfficeMicrosoft Office Compatibility Pack FOR Word Excel PPT 2007Microsoft Office Word ViewerMicrosoft Open XML File Format Converter+310/12/200816/6/2026
Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the File Information Block (FIB), which bypasses an initialization step and triggers an "arbitrary free," aka "Word Memory Corruption…
ModificadaAlta (7.1)27%—Microsoft Outlook ExpressMicrosoft Windows Mail13/8/200816/6/2026
The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access restrictions and read arbitrary files via an mhtml: URI in…
ModificadaMedia (4.3)25%—Microsoft Exchange ServerMicrosoft Outlook WEB Access8/7/200816/6/2026
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.
ModificadaAlta (7.5)17%—Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+137/7/200816/6/2026
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times…
ModificadaBaja (1.9)1.5%—Microsoft Outlook WEB Access12/5/200816/6/2026
Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information.
ModificadaAlta (9.3)55%—Microsoft Outlook ExpressMicrosoft Windows Mail9/10/200716/6/2026
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.
ModificadaAlta (8.8)13%—Microsoft OutlookMicrosoft Outlook Express27/7/200716/6/2026
Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking…