Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2833▲ 195 respecto a la semana anterior
Críticas / altas1316▼ 117 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1385 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 45% | 💥 Exploit | Avaya Converged Communications ServerRedhat Fedora CoreTrustix Secure LinuxAvaya Integrated Management+4 | 27/7/2004 | 16/6/2026 | La función strip_tags en PHP 4.x hasta 4.3.7, y 5.x hasta 5.0.0RC3, no filtra caractéres null() dentro de nombreres de etiquetas cuanto se restringe la entrada a etiquetas permitidas, lo que permite que etiquetas peligrosas sean procesadas por navegadores como Internet Explorer y Safari, que ignoran caractéres nulos y… | |
| Modificada | Media (5) | 1.4% | — | Mitel 3300 Integrated Communications PlatformAI | 28/2/2004 | 16/6/2026 | The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 generates easily predictable web session IDs, which allows remote attackers to hijack other sessions via the parentsessionid cookie. | |
| Modificada | Alta (7.5) | 3.8% | — | Nortel Business Communications ManagerNortel 802.11 Wireless IP GatewayNortel Succession Communication Server 1000 | 17/2/2004 | 16/6/2026 | Múltiples vulnerabilidades en la implementación del protocolo H.323 en Nortel Networks Communications Manager (BCM), Succession 1000 IP Trunk and IP Peer Networking, y 802.11 Wireless IP Gateway permite a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario, como se demostró… | |
| Modificada | Alta (7.5) | 7.6% | — | Apache Http ServerApache MOD Digest AppleAvaya Communication ManagerAvaya Intuity Audix LX+10 | 3/2/2004 | 16/6/2026 | mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials. | |
| Modificada | Media (5) | 2.0% | — | Whale Communications E-gap | 31/12/2003 | 16/6/2026 | Whale Communications e-Gap 2.5 on Windows 2000 allows remote attackers to obtain the source code for the login page via the HTTP TRACE method, which bypasses the preprocessor. | |
| Modificada | Alta (7.5) | 4.7% | — | Nortel Succession Communication Server 2000 | 31/12/2003 | 16/6/2026 | The Session Initiation Protocol (SIP) implementation in Nortel Networks Succession Communication Server 2000, when using SIP-T, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted INVITE messages, as demonstrated by the OUSPG PROTOS c07-sip test suite. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 7/8/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos (XSS) en search.asp de Snitz Forums 3.4.03 y anteriores permite a atacantes remotos ejecutar script web arbitrario mediante el parámetro Search. | |
| Modificada | Alta (10) | 3.8% | — | Snitz Communications Snitz Forums 2000 | 7/8/2003 | 16/6/2026 | password.asp en Snitz Forums 3.4.03 y anteriores permite a atacantes remotos reestablecer contraseñas y ganar privilegios de otros usuarios mediante una petición directa a password.asp con un identificador (id) de miembro modificado. | |
| Modificada | Alta (10) | 1.8% | — | Snitz Communications Snitz Forums 2000 | 7/8/2003 | 16/6/2026 | Snitz Forums 3.4.03 y anteriores permite a atacantes ganar privilegios como otros usuarios robando y reutlizando la contraseña cifrada después de haber obtenido un identificador de sesión válido. | |
| Modificada | Alta (7.5) | 2.4% | — | Snitz Communications Snitz Forums 2000 | 16/6/2003 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Snitz Forums 2000 anteriores a la 3.3.03 permite que atacantes remotos ejecuten procedimientos almacenados arbitrarios mediante la variable Email. | |
| Modificada | Media (6.4) | 2.0% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes. | |
| Modificada | Alta (10) | 5.8% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method. | |
| Modificada | Media (5) | 1.9% | — | Blue World Communications Lasso WEB Data Engine | 31/12/2002 | 16/6/2026 | Buffer overflow in Blue World Lasso Web Data Engine 3.6.5 allows remote attackers to cause a denial of service via a long URL. | |
| Modificada | Media (5) | 1.6% | — | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. | |
| Modificada | Media (4.6) | 1.0% | 💥 Exploit | Netscape Communicator | 31/12/2002 | 16/6/2026 | Buffer overflow in Composer in Netscape 4.77 allows local users to overwrite process memory and execute arbitrary code via a font tag with a long face attribute. | |
| Modificada | Media (5) | 1.1% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message. | |
| Modificada | Media (5) | 1.3% | — | Netscape Communicator | 29/11/2002 | 16/6/2026 | Netscape Communicator 4.x permite a atacantes usar un enlace para robar las preferencias de un usuario, incluyendo información potencialmente sensible como historia de URLs, direcciones de correo electrónico, y posiblemente sus contraseñas, mediante la redefinición de la función user_pref() y accediendo al fichero… | |
| Modificada | Alta (10) | 2.1% | 💥 Exploit | Ruslan Communications Body Builder | 4/10/2002 | 16/6/2026 | SQL injection vulnerability in Ruslan <Body>Builder allows remote attackers to gain administrative privileges via a "'--" sequence in the username and password. | |
| Modificada | Media (5) | 8.3% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | Directory traversal vulnerability in NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to read arbitrary files via a URL-encoded request to com.newatlanta.servletexec.JSP10Servlet containing "..%5c" (modified dot-dot) sequences. | |
| Modificada | Media (5) | 7.6% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | The default configuration of NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to determine the path of the web root via a direct request to com.newatlanta.servletexec.JSP10Servlet without a filename, which leaks the pathname in an error message. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | NEW Atlanta Communications Servletexec Isapi | 4/10/2002 | 16/6/2026 | NewAtlanta ServletExec ISAPI 4.1 allows remote attackers to cause a denial of service (crash) via (1) a request for a long .jsp file, or (2) a long URL sent directly to com.newatlanta.servletexec.JSP10Servlet. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Snitz Communications Snitz Forums 2000 | 25/6/2002 | 16/6/2026 | Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary script as other Forums 2000 users via Javascript in an IMG tag. | |
| Modificada | Media (4.6) | 0.43% | — | Hotline Communications Hotline Connect | 25/6/2002 | 16/6/2026 | Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords. | |
| Modificada | Alta (7.5) | 3.5% | — | MozillaNetscape CommunicatorNetscape Navigator | 18/6/2002 | 16/6/2026 | Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. |