Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.4% | — | AOL Instant Messenger | 2/5/2005 | 16/6/2026 | AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow. | |
| Modificada | Alta (7.5) | 23% | — | Microsoft MSN Messenger | 12/4/2005 | 16/6/2026 | GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width. | |
| Modificada | Media (4.6) | 0.46% | — | Yahoo Messenger | 18/2/2005 | 16/6/2026 | The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions. | |
| Modificada | Media (5) | 1.0% | — | Yahoo Messenger | 17/2/2005 | 16/6/2026 | Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions. | |
| Modificada | Media (5) | 1.4% | — | Gadu-gadu Instant Messenger | 10/1/2005 | 16/6/2026 | Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype. | |
| Modificada | Media (5) | 1.6% | — | Gadu-gadu Instant Messenger | 10/1/2005 | 16/6/2026 | Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length. | |
| Modificada | Alta (10) | 6.2% | — | Gadu-gadu Instant Messenger | 10/1/2005 | 16/6/2026 | Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename. | |
| Modificada | Media (5) | 1.7% | — | Gadu-gadu Instant Messenger | 10/1/2005 | 16/6/2026 | Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype. | |
| Modificada | Alta (7.5) | 1.6% | — | Gadu-gadu Instant Messenger | 10/1/2005 | 16/6/2026 | Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Gadu-gadu Instant Messenger | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | AOL Instant Messenger | 31/12/2004 | 16/6/2026 | The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations. | |
| Modificada | Media (5) | 1.6% | — | Gadu-gadu Instant Messenger | 31/12/2004 | 16/6/2026 | Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities. | |
| Modificada | Baja (2.6) | 1.3% | — | Gadu-gadu Instant Messenger | 31/12/2004 | 16/6/2026 | Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters. | |
| Modificada | Media (5) | 1.3% | — | Gadu-gadu Instant Messenger | 31/12/2004 | 16/6/2026 | Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images. | |
| Modificada | Alta (7.5) | 4.6% | — | Vypress MessengerAI | 31/12/2004 | 16/6/2026 | Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field. | |
| Modificada | Alta (10) | 66% | 💥 Exploit | AOL Instant Messenger | 23/11/2004 | 16/6/2026 | Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message. | |
| Modificada | Alta (10) | 82% | 💥 Exploit | Greg Roelofs LibpngMicrosoft MSN MessengerMicrosoft Windows Media PlayerMicrosoft Windows Messenger+2 | 23/11/2004 | 16/6/2026 | Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3)… | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Leadmind Popmessenger | 24/9/2004 | 16/6/2026 | The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash. | |
| Modificada | Alta (7.5) | 3.3% | — | Gadu-gadu Instant Messenger | 12/9/2004 | 16/6/2026 | Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message. | |
| Modificada | Media (5) | 22% | — | Microsoft MSN Messenger | 15/4/2004 | 16/6/2026 | Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 3.6% | — | Yahoo Messenger | 3/2/2004 | 16/6/2026 | Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature. | |
| Modificada | Alta (10) | 4.6% | — | AOL Instant Messenger | 31/12/2003 | 16/6/2026 | Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name. | |
| Modificada | Baja (2.6) | 4.5% | 💥 Exploit | Yahoo Messenger | 31/12/2003 | 16/6/2026 | Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID. | |
| Modificada | Alta (10) | 5.3% | — | Hiroaki Shirouzu IP Messenger | 16/6/2003 | 16/6/2026 | Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file. | |
| Modificada | Media (5) | 16% | — | Microsoft MSN Messenger | 31/12/2002 | 16/6/2026 | Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header. |