Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1972 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)49%—Microsoft Internet Explorer13/6/200616/6/2026
Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."
ModificadaAlta (9.3)40%💥 ExploitMicrosoft Internet Explorer13/6/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the…
ModificadaAlta (7.6)20%—Microsoft IEMicrosoft Internet Explorer13/6/200616/6/2026
Vulnerabilidad no especificada en Microsoft Internet Explorer 5.01 SP4 y 6 SP1 y anteriores permite a atacantes asistidos por el usuario ejecutar código de forma arbitraria a través de una página web manipulada que dispara una corrupción de memoria cuando se guarda como un archivo multipart HTML (.mht)
ModificadaMedia (4.3)19%—Microsoft Internet Explorer13/6/200616/6/2026
Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address…
ModificadaMedia (6.8)35%—Microsoft IEMicrosoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows XP13/6/200616/6/2026
Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.
ModificadaAlta (7.5)1.2%—Pineapple Technologies Lore6/6/200616/6/2026
SQL injection vulnerability in comment.php in Pineapple Technologies Lore 1.5.6 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.
ModificadaBaja (2.6)48%💥 ExploitMicrosoft IEMicrosoft Internet Explorer2/6/200616/6/2026
Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.
ModificadaAlta (9.3)33%—Microsoft Internet Explorer5/5/200616/6/2026
Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.
ModificadaMedia (5.1)23%💥 ExploitMicrosoft IEMicrosoft Internet Explorer29/4/200616/6/2026
Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race…
ModificadaMedia (5)13%—Microsoft Internet Explorer26/4/200616/6/2026
Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an…
ModificadaBaja (2.6)40%💥 ExploitMicrosoft Internet Explorer25/4/200616/6/2026
mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that…
ModificadaMedia (4)32%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.
ModificadaBaja (2.6)32%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is…
ModificadaAlta (7.5)70%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.
ModificadaAlta (10)58%💥 ExploitMicrosoft IEMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.
ModificadaAlta (7.5)58%💥 ExploitMicrosoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb10111/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.
ModificadaAlta (10)62%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."
ModificadaAlta (10)62%💥 ExploitMicrosoft Internet Explorer11/4/200616/6/2026
Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.
ModificadaMedia (4.3)26%💥 ExploitMicrosoft Internet Explorer5/4/200616/6/2026
Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: this…
ModificadaMedia (4.3)1.8%—Nikolay Avrionov Explorer XP29/3/200616/6/2026
Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. NOTE: it is possible that this issue is resultant from CVE-2006-1492.
ModificadaMedia (5)2.4%—Nikolay Avrionov Explorer XP29/3/200616/6/2026
Directory traversal vulnerability in dir.php in Explorer XP allows remote attackers to read arbitrary files via the chemin parameter.
ModificadaAlta (7.5)55%💥 ExploitMicrosoft IEMicrosoft Internet Explorer24/3/200616/6/2026
Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.
ModificadaAlta (9.3)68%💥 ExploitMicrosoft IEMicrosoft Internet Explorer23/3/200616/6/2026
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
ModificadaAlta (7.5)67%💥 ExploitMicrosoft Internet Explorer7/3/200616/6/2026
Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.
ModificadaAlta (7.5)14%—Microsoft Internet Explorer21/2/200616/6/2026
The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location"…
Orbitaley — Vulnerabilidades