Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2766▲ 12 respecto a la semana anterior
Críticas / altas1276▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 227 respecto a la semana anterior
1419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Compuware Driverstudio | 22/9/2005 | 16/6/2026 | Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110. | |
| Modificada | Alta (7.5) | 1.8% | — | Compuware Driverstudio | 22/9/2005 | 16/6/2026 | Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | ATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+2 | 19/8/2005 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the… | |
| Modificada | Baja (2.1) | 0.33% | — | Cerulean Studios Trillian PRO | 3/8/2005 | 16/6/2026 | Trillian Pro 3.1 build 121, cuando comprueba el e-mail de Yahoo, almacena el password en texto plano en un fichero legible y no borra ese fichero después del login, lo que permite que usuarios locales conozcan esa información. | |
| Modificada | Media (5) | 1.7% | — | Firefly Studios Stronghold 2 | 30/5/2005 | 16/6/2026 | Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception. | |
| Modificada | Media (5) | 1.7% | — | Compuware Softice Driverstudio | 29/5/2005 | 16/6/2026 | The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer. | |
| Modificada | Media (6.8) | 1.5% | — | Positive Software Sitestudio | 16/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere. | |
| Modificada | Media (5) | 1.5% | — | Cerulean Studios Trillian | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header. | |
| Modificada | Media (5) | 1.1% | — | Cerulean Studios Trillian | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Stormy Studios Knet | 2/5/2005 | 16/6/2026 | Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (7.5) | 5.3% | 💥 Exploit | Cerulean Studios TrillianCerulean Studios Trillian PRO | 2/3/2005 | 16/6/2026 | Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file. | |
| Modificada | Alta (7.2) | 0.36% | — | Macromedia ContributeMacromedia Studio | 31/12/2004 | 16/6/2026 | The Macromedia installers and e-licensing client on Mac OS X, as used for Macromedia Contribute 2, Director, Dreamweaver, Fireworks, Flash, and Studio, install the AuthenticationService setuid and writable by other users, which allows local users to gain privileges by modifying the program. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Cerulean Studios Trillian | 31/12/2004 | 16/6/2026 | Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character. | |
| Modificada | Media (5) | 1.8% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service (infinite loop) via user re-registration. | |
| Modificada | Alta (7.5) | 3.8% | — | Cerulean Studios TrillianCerulean Studios Trillian PRO | 31/12/2004 | 16/6/2026 | Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 3.7% | — | Cerulean Studios TrillianCerulean Studios Trillian PRO | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in Trillian 0.71 through 0.74f and Trillian Pro 1.0 through 2.01 allows remote attackers to execute arbitrary code via a Yahoo Messenger packet with a long key name. | |
| Modificada | Media (5) | 1.6% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8 allows remote attackers to cause a denial of service a message with an empty <priority/> tag. | |
| Modificada | Media (5) | 1.4% | — | Jabberstudio Jabber Gadu-gadu Transport | 31/12/2004 | 16/6/2026 | The roster import functionality in Jabber Gadu-Gadu Transport (a.k.a. jabber-gg-transport) 2.0.x before 2.0.8, when using libgadu 1.0 and later, allows attackers to cause a denial of service via unknown vectors. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Desbordamiento de búfer en el motor de proceso de JPEG (JPG) en GDIPlus.dll, usado en varios productos de Microsoft, permite a atacantes remotos ejecutar código de su elección mediante un campo de longitud JPEG COM pequeño que es normalizado a una longitud de entero grande antes de una operación de copia de memoria. | |
| Modificada | Media (5) | 2.4% | — | Jabberstudio JabberdJabberstudio Jadc2s | 21/9/2004 | 16/6/2026 | The expat XML parser code, as used in the open source Jabber (jabberd) 1.4.3 and earlier, jadc2s 0.9.0 and earlier, and possibly other packages, allows remote attackers to cause a denial of service (application crash) via a malformed packet to a socket that accepts XML connections. | |
| Modificada | Alta (7.5) | 72% | 💥 Exploit | BEA Weblogic ServerBorland Software J BuilderBusinessobjects Crystal EnterpriseBusinessobjects Crystal Enterprise Java SDK+5 | 6/8/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en los visores web de Business Objects Crystal Reports 9 and 10, y Crystal Enterprise 9 o 10, usados en Visual Studio .NET 2003 y Outlook 2003 con Business Contact Manager, Microsoft Business Solutions CRM 1.2, y otros productos, permiten a atacantes remotos leer y… | |
| Modificada | Alta (7.5) | 2.8% | — | X2 Studios Xmms Remote | 31/12/2003 | 16/6/2026 | XMMS.pm in X2 XMMS Remote, as obtained from the vendor server between 4 AM 11 AM PST on May 7, 2003, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to TCP port 8086. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Ashwebstudio Ashnews | 31/12/2003 | 16/6/2026 | PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbitrary remote files via a URL in the pathtoashnews parameter to (1) ashnews.php and (2) ashheadlines.php. | |
| Modificada | Media (5) | 1.3% | — | Cerulean Studios Trillian | 18/8/2003 | 16/6/2026 | Trillian 1.0 Pro y 0.74 Freeware permite a atacantes remotos causar una denegación de servicio (caída) mediente un mensaje TypingUser en el que la cadena "TypingUser" ha sido modificada. | |
| Modificada | Alta (7.5) | 9.4% | 💥 Exploit | Cerulean Studios Trillian | 2/4/2003 | 16/6/2026 | Multiples desbordamiento de búfer en el componente IRC de Trillian 0.73 y 0.74 permite a servidores IRC remotos malintencionados causar la Denegación de Servicios y posiblemente la ejecución de código arbitrario mediante: una respuesta larga del servidor. un JOIN con un nombre de canal largo. un mensaje largo raw 221.… |