Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.4%—AOL Instant Messenger2/5/200516/6/2026
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a long filename, possibly caused by a buffer overflow.
ModificadaAlta (7.5)23%—Microsoft MSN Messenger12/4/200516/6/2026
GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.
ModificadaMedia (4.6)0.46%—Yahoo Messenger18/2/200516/6/2026
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
ModificadaMedia (5)1.0%—Yahoo Messenger17/2/200516/6/2026
Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces and multiple file extensions.
ModificadaMedia (5)1.4%—Gadu-gadu Instant Messenger10/1/200516/6/2026
Gadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CTCP packet that contains a 1 as the type and a 4 as the subtype.
ModificadaMedia (5)1.6%—Gadu-gadu Instant Messenger10/1/200516/6/2026
Integer overflow in Gadu-Gadu allows remote attackers to cause a denial of service (disk consumption) via a user packet to the DCC file transfer capability with an invalid file length.
ModificadaAlta (10)6.2%—Gadu-gadu Instant Messenger10/1/200516/6/2026
Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.
ModificadaMedia (5)1.7%—Gadu-gadu Instant Messenger10/1/200516/6/2026
Directory traversal vulnerability in Gadu-Gadu allows remote attackers to read arbitrary files via .. (dot dot) sequences in a DCC connection with a CTCP packet that contains a 1 as the type and a 4 as the subtype.
ModificadaAlta (7.5)1.6%—Gadu-gadu Instant Messenger10/1/200516/6/2026
Cross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) news:// URLs, a different vulnerability than CVE-2004-1410.
ModificadaMedia (4.3)1.7%💥 ExploitGadu-gadu Instant Messenger31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary web script via a URL, which is echoed in a popup window that displays a parsing error message, a different vulnerability than CVE-2004-1229.
ModificadaAlta (7.5)2.7%💥 ExploitAOL Instant Messenger31/12/200416/6/2026
The Buddy icon file for AOL Instant Messenger (AIM) 4.3 through 5.5 is created in a predictable location, which may allow remote attackers to use a shell: URI to exploit other vulnerabilities that involve predictable locations.
ModificadaMedia (5)1.6%—Gadu-gadu Instant Messenger31/12/200416/6/2026
Gadu-Gadu allows remote attackers to bypass the "image send" option by sending a very small image file, which could be used in conjunction with image-related vulnerabilities.
ModificadaBaja (2.6)1.3%—Gadu-gadu Instant Messenger31/12/200416/6/2026
Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.
ModificadaMedia (5)1.3%—Gadu-gadu Instant Messenger31/12/200416/6/2026
Gadu-Gadu 6.1 build 156 allows remote attackers to cause a denial of service (application hang) via a message that contains many special strings that are converted to images.
ModificadaAlta (7.5)4.6%—Vypress MessengerAI31/12/200416/6/2026
Buffer overflow in Vypress Messenger 3.5.1 and earlier allows remote attackers to execute arbitrary code via a message with a long first field.
ModificadaAlta (10)66%💥 ExploitAOL Instant Messenger23/11/200416/6/2026
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.
ModificadaAlta (10)82%💥 ExploitGreg Roelofs LibpngMicrosoft MSN MessengerMicrosoft Windows Media PlayerMicrosoft Windows Messenger+223/11/200416/6/2026
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3)…
ModificadaMedia (5)3.5%💥 ExploitLeadmind Popmessenger24/9/200416/6/2026
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.
ModificadaAlta (7.5)3.3%—Gadu-gadu Instant Messenger12/9/200416/6/2026
Heap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG_MSG_IMAGE_REPLY message.
ModificadaMedia (5)22%—Microsoft MSN Messenger15/4/200416/6/2026
Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.
ModificadaAlta (7.5)3.6%—Yahoo Messenger3/2/200416/6/2026
Buffer overflow in Yahoo Instant Messenger 5.6.0.1351 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in the download feature.
ModificadaAlta (10)4.6%—AOL Instant Messenger31/12/200316/6/2026
Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.
ModificadaBaja (2.6)4.5%💥 ExploitYahoo Messenger31/12/200316/6/2026
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send request (sendfile) with a large number of "%" (percent) characters after the Yahoo ID.
ModificadaAlta (10)5.3%—Hiroaki Shirouzu IP Messenger16/6/200316/6/2026
Buffer overflow in the file & folder transfer mechanism for IP Messenger for Win 2.00 through 2.02 allows remote attackers to execute arbitrary code via file with a long filename, which triggers the overflow when the user saves the file.
ModificadaMedia (5)16%—Microsoft MSN Messenger31/12/200216/6/2026
Buffer overflow in Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via a long FN (font) argument in the message header.
Orbitaley — Vulnerabilidades