Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Firebirdsql FirebirdMozillaNetscape Navigator | 27/7/2004 | 16/6/2026 | The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability. | |
| Modificada | Media (5) | 1.1% | — | Netscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 4 sends Referer headers containing https:// URLs in requests for http:// URLs, which allows remote attackers to obtain potentially sensitive information by reading Referer log data. | |
| Modificada | Media (4.3) | 2.1% | 💥 Exploit | Netscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 7.0 allows remote attackers to cause a denial of service (crash) via a web page with an invalid regular expression argument to the JavaScript reformatDate function. | |
| Modificada | Media (5) | 1.2% | — | Mozilla FirefoxNetscape Navigator | 31/12/2003 | 16/6/2026 | Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end. | |
| Modificada | Baja (2.1) | 0.39% | — | MozillaNetscape Navigator | 31/12/2003 | 16/6/2026 | Netscape 7.0 and Mozilla 5.0 do not immediately delete messages in the trash folder when users select the 'Empty Trash' option, which could allow local users to access deleted messages. | |
| Modificada | Alta (7.5) | 2.7% | — | Netscape Navigator | 18/8/2003 | 16/6/2026 | Buffer overflow in the Client Detection Tool (CDT) plugin (npcdt.dll) for Netscape 7.02 allows remote attackers to execute arbitrary code via an attachment with a long filename. | |
| Modificada | Alta (7.5) | 3.5% | — | MozillaNetscape Navigator | 31/12/2002 | 16/6/2026 | Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel. | |
| Modificada | Media (5) | 3.9% | 💥 Exploit | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no new mail) via a mail message containing a dot (.) at a newline, which is interpreted as the end of the message. | |
| Modificada | Media (5) | 1.6% | — | MozillaNetscape CommunicatorNetscape Navigator | 31/12/2002 | 16/6/2026 | Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain. | |
| Modificada | Alta (7.5) | 3.7% | — | MozillaNetscape Navigator | 29/11/2002 | 16/6/2026 | Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar file, which overflows a buffer during decompression. | |
| Modificada | Alta (7.5) | 4.3% | — | MozillaNetscape NavigatorOpera Software Opera WEB Browser | 4/10/2002 | 16/6/2026 | Netscape 6.2.3 and earlier, and Mozilla 1.0.1, allow remote attackers to corrupt heap memory and execute arbitrary code via a GIF image with a zero width. | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft Internet ExplorerMozillaNetscape Navigator | 12/8/2002 | 16/6/2026 | The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted… | |
| Modificada | Media (5) | 1.0% | — | MozillaNetscape Navigator | 25/6/2002 | 16/6/2026 | The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property. | |
| Modificada | Media (5) | 2.4% | — | Galeon BrowserMozillaNetscape Navigator | 18/6/2002 | 16/6/2026 | Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to determine the existence of files on the client system via a LINK element in a Cascading Style Sheet (CSS) page that causes an HTTP redirect. | |
| Modificada | Alta (7.5) | 3.5% | — | MozillaNetscape CommunicatorNetscape Navigator | 18/6/2002 | 16/6/2026 | Buffer overflow in Netscape 6 and Mozilla 1.0 RC1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long channel name in an IRC URI. | |
| Modificada | Alta (7.5) | 1.7% | — | Logitech Cordless FreedomLogitech Cordless Freedom NavigatorLogitech Cordless Freedom PROLogitech Cordless Itouch Keyboard | 18/10/2001 | 16/6/2026 | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 2.6% | — | Netscape CommunicatorNetscape Navigator | 9/1/2001 | 16/6/2026 | Buffer overflow in the HTML parser for Netscape 4.75 and earlier allows remote attackers to execute arbitrary commands via a long password value in a form field. | |
| Modificada | Media (5) | 1.3% | — | Netscape CommunicatorNetscape Navigator | 12/1/2000 | 16/6/2026 | Netscape Mail Notification (nsnotify) utility in Netscape Communicator uses IMAP without SSL, even if the user has set a preference for Communicator to use an SSL connection, allowing a remote attacker to sniff usernames and passwords in plaintext. | |
| Modificada | Alta (7.5) | 2.5% | — | Netscape CommunicatorNetscape Navigator | 24/11/1999 | 16/6/2026 | Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file. | |
| Modificada | Baja (2.6) | 4.8% | — | Microsoft IEMicrosoft Internet ExplorerNetscape Navigator | 1/11/1999 | 16/6/2026 | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | |
| Modificada | Baja (2.6) | 1.4% | — | Netscape CommunicatorNetscape Navigator | 24/5/1999 | 16/6/2026 | When Javascript is embedded within the TITLE tag, Netscape Communicator allows a remote attacker to use the "about" protocol to gain access to browser information. | |
| Modificada | Alta (7.5) | 3.6% | — | Netscape CommunicatorNetscape NavigatorSUN Java | 1/3/1999 | 16/6/2026 | The byte code verifier component of the Java Virtual Machine (JVM) allows remote execution through malicious web pages. | |
| Modificada | Baja (2.6) | 17% | 💥 Exploit | Microsoft Internet ExplorerNetscape Navigator | 1/12/1998 | 16/6/2026 | Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. | |
| Modificada | Baja (3.7) | 0.37% | — | Netscape Navigator | 29/3/1996 | 16/6/2026 | Java Bytecode Verifier allows malicious applets to execute arbitrary commands as the user of the applet. | |
| Modificada | Alta (7.5) | 1.6% | — | Netscape NavigatorSUN Java | 1/3/1996 | 16/6/2026 | The Java Applet Security Manager implementation in Netscape Navigator 2.0 and Java Developer's Kit 1.0 allows an applet to connect to arbitrary hosts. |