Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)62%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
ModificadaAlta (7.5)70%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
ModificadaAlta (7.5)58%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
ModificadaAlta (10)58%💥 ExploitMicrosoft IEMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
ModificadaBaja (2.6)32%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is…
ModificadaMedia (4)32%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.
ModificadaAlta (10)62%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."
ModificadaMedia (4.3)26%💥 ExploitMicrosoft Internet Explorer5/4/200616/6/2026
Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: this…
ModificadaAlta (7.5)55%💥 ExploitMicrosoft IEMicrosoft Internet Explorer24/3/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
ModificadaAlta (9.3)68%💥 ExploitMicrosoft IEMicrosoft Internet Explorer23/3/200616/6/2026
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
ModificadaAlta (7.5)67%💥 ExploitMicrosoft Internet Explorer7/3/200616/6/2026
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.
ModificadaAlta (7.5)14%—Microsoft Internet Explorer21/2/200616/6/2026
The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location"…
ModificadaMedia (4)7.6%—Microsoft Internet Explorer19/2/200616/6/2026
Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate…
ModificadaMedia (5)15%—Microsoft Internet Explorer8/2/200616/6/2026
jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference.
ModificadaAlta (7.5)20%—Microsoft IEMicrosoft Internet Explorer27/1/200616/6/2026
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes…
ModificadaAlta (7.1)12%—Microsoft Internet Explorer31/12/200516/6/2026
The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
ModificadaAlta (7.1)9.2%—Microsoft Internet Explorer31/12/200516/6/2026
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
ModificadaMedia (5)16%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows 2003 Server+231/12/200516/6/2026
Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related…
ModificadaAlta (7.1)9.2%—Microsoft Internet Explorer31/12/200516/6/2026
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
ModificadaMedia (5)14%—Microsoft Internet Explorer31/12/200516/6/2026
Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
ModificadaAlta (7.5)11%—Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10131/12/200516/6/2026
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method…
ModificadaAlta (7.8)11%—Microsoft Internet Explorer31/12/200516/6/2026
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
ModificadaMedia (5.1)5.5%—Microsoft IEMicrosoft Internet Explorer31/12/200516/6/2026
Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious…
ModificadaMedia (5)35%—Microsoft IEMicrosoft Internet Explorer14/12/200516/6/2026
Microsoft Interntet Explorer 5.01, 5.5 y 6, cuando usan un servidor proxy HTTPS que requiere autenticación básica, envía la URL en texto claro, lo que permite a atacantes remotos obtener información sensible, tcc "Vulnerabilidad proxy HTTPS"
ModificadaMedia (5.1)19%—Microsoft IEMicrosoft Internet Explorer14/12/200516/6/2026
Múltiples errores de diseño en Microsoft Internet Explorer 5.01, 5.5 y 6 permiten a atacantes con la intervención del usuario ejecutar código de su elección mediante (1) superponiendo y ventana nueva maliciosa a un cuadro de descarga de fichero, y entonces (2) usando un atajo de teclado y demorando la visualización…