Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
203 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 25% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 12/6/2007 | 16/6/2026 | The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information… | |
| Modificada | Media (4.3) | 25% | — | Microsoft Outlook ExpressMicrosoft Windows Mail | 12/6/2007 | 16/6/2026 | A component in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle certain HTTP headers when processing MHTML protocol URLs, which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "URL Parsing Cross Domain Information Disclosure… | |
| Analizada | Alta (8.8) | 43% | ⚠ Explotación activa | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 3/2/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks. | |
| Modificada | Alta (9.3) | 33% | — | Microsoft OfficeMicrosoft Outlook | 9/1/2007 | 16/6/2026 | Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file. | |
| Modificada | Alta (9.3) | 38% | — | Microsoft OfficeMicrosoft Outlook | 9/1/2007 | 16/6/2026 | Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsoft Outlook Advanced Find Vulnerability." | |
| Modificada | Media (4.3) | 32% | — | Microsoft OfficeMicrosoft Outlook | 31/12/2006 | 16/6/2026 | Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Microsoft IEMicrosoft OutlookMicrosoft Windows XP | 20/12/2006 | 16/6/2026 | The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML. | |
| Modificada | Media (6.8) | 29% | — | Microsoft Outlook Express | 13/12/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file. | |
| Modificada | Alta (9.3) | 13% | — | Microsoft AccessMicrosoft ExcelMicrosoft Excel ViewerMicrosoft Frontpage+10 | 10/10/2006 | 16/6/2026 | Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876. | |
| Modificada | Alta (9.3) | 61% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft Outlook | 19/9/2006 | 16/6/2026 | Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag. | |
| Modificada | Media (4.3) | 40% | 💥 Exploit | Microsoft Outlook Express | 1/5/2006 | 16/6/2026 | A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability." | |
| Modificada | Media (5) | 15% | — | Microsoft Outlook | 26/4/2006 | 16/6/2026 | Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an attachment. NOTE:… | |
| Modificada | Media (5.1) | 24% | — | Microsoft Outlook Express | 12/4/2006 | 16/6/2026 | Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values. | |
| Modificada | Alta (7.5) | 46% | — | Microsoft Exchange ServerMicrosoft OfficeMicrosoft Outlook | 10/1/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation. | |
| Modificada | Media (4.3) | 12% | — | Microsoft Outlook Express Book Control | 31/12/2005 | 16/6/2026 | The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within Internet Explorer. | |
| Modificada | Media (5) | 13% | — | Microsoft Outlook Express | 12/7/2005 | 16/6/2026 | Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 74% | 💥 Exploit | Microsoft Outlook Express | 14/6/2005 | 16/6/2026 | Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field. | |
| Modificada | Media (4.6) | 1.3% | — | Microsoft Outlook Connector | 2/5/2005 | 16/6/2026 | Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy. | |
| Modificada | Media (5) | 9.4% | — | Microsoft OutlookMicrosoft Outlook WEB Access | 2/5/2005 | 16/6/2026 | Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses. | |
| Modificada | Media (5.8) | 8.6% | — | Microsoft Outlook Express | 31/12/2004 | 16/6/2026 | Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook context, and facilitate phishing attacks via a "BASE HREF" with the target set to "_top". | |
| Modificada | Media (5) | 26% | — | Microsoft Outlook Express | 31/12/2004 | 16/6/2026 | Outlook Express 6.0, when sending multipart e-mail messages using the "Break apart messages larger than" setting, leaks the BCC recipients of the message to the addresses listed in the To and CC fields, which may allow remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 13% | — | Microsoft Outlook | 31/12/2004 | 16/6/2026 | Microsoft Outlook 2000 and 2003, when configured to use Microsoft Word 2000 or 2003 as the e-mail editor and when forwarding e-mail, does not properly handle an opening OBJECT tag that does not have a closing OBJECT tag, which causes Outlook to automatically download the URI in the data property of the OBJECT tag and… | |
| Modificada | Media (5) | 17% | — | Microsoft IEMicrosoft Internet ExplorerMicrosoft Outlook | 23/11/2004 | 16/6/2026 | Microsoft Internet Explorer 6.0, Outlook 2002, and Outlook 2003 allow remote attackers to cause a denial of service (CPU consumption), if "Do not save encrypted pages to disk" is disabled, via a web site or HTML e-mail that contains two null characters (%00) after the host name. | |
| Modificada | Alta (9.3) | 49% | 💥 Exploit | Microsoft .net FrameworkMicrosoft Digital Image PROMicrosoft Digital Image SuiteMicrosoft Excel+20 | 28/9/2004 | 16/6/2026 | Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Microsoft Outlook | 18/8/2004 | 16/6/2026 | Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a remote site via an HTML e-mail message containing a Vector Markup Language (VML) entity whose src parameter points to the remote site, which could allow remote attackers to know when a message has been… |