Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1897 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 18% | — | Microsoft Internet Explorer | 31/12/1999 | 16/6/2026 | Buffer overflow in Internet Explorer 4.01 and earlier allows remote attackers to execute arbitrary commands via a long URL with the "mk:" protocol, aka the "MK Overrun security issue." | |
| Modificada | Media (5.1) | 13% | — | Microsoft Internet Explorer | 31/12/1999 | 16/6/2026 | Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. | |
| Modificada | Alta (7.5) | 6.4% | — | Microsoft Internet Explorer | 31/12/1999 | 16/6/2026 | Internet Explorer 4 treats a 32-bit number ("dotless IP address") in the a URL as the hostname instead of an IP address, which causes IE to apply Local Intranet Zone settings to the resulting web page, allowing remote malicious web servers to conduct unauthorized activities by using URLs that contain the dotless IP… | |
| Modificada | Media (5) | 17% | — | Microsoft Internet Explorer | 31/12/1999 | 16/6/2026 | Internet Explorer 4.0 allows remote attackers to read arbitrary text and HTML files on the user's machine via a small IFRAME that uses Dynamic HTML (DHTML) to send the data to the attacker, aka the Freiburg text-viewing issue. | |
| Modificada | Baja (2.6) | 23% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 23/12/1999 | 16/6/2026 | Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Microsoft Internet Explorer | 8/12/1999 | 16/6/2026 | Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Explorer | 2/12/1999 | 16/6/2026 | Internet Explorer 5 allows a remote attacker to modify the IE client's proxy configuration via a malicious Web Proxy Auto-Discovery (WPAD) server. | |
| Modificada | Baja (2.6) | 13% | 💥 Exploit | Microsoft Internet Explorer | 17/11/1999 | 16/6/2026 | Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. | |
| Modificada | Media (5) | 9.8% | 💥 Exploit | Microsoft Internet Explorer | 14/11/1999 | 16/6/2026 | Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client. | |
| Modificada | Media (5.1) | 7.7% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerMicrosoft OutlookMicrosoft Outlook Express | 11/11/1999 | 16/6/2026 | A Microsoft ActiveX control allows a remote attacker to execute a malicious cabinet file via an attachment and an embedded script in an HTML mail, aka the "Active Setup Control" vulnerability. | |
| Modificada | Alta (7.5) | 5.2% | — | Microsoft Internet ExplorerMicrosoft Word | 1/11/1999 | 16/6/2026 | Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message. | |
| Modificada | Baja (2.6) | 4.8% | — | Microsoft IEMicrosoft Internet ExplorerNetscape Navigator | 1/11/1999 | 16/6/2026 | By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. | |
| Modificada | Media (5.1) | 19% | 💥 Exploit | Microsoft Internet Explorer | 31/10/1999 | 16/6/2026 | Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. | |
| Modificada | Media (4.3) | 18% | 💥 Exploit | Microsoft Internet Explorer | 1/10/1999 | 16/6/2026 | Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME. | |
| Modificada | Media (5.1) | 19% | 💥 Exploit | Microsoft Internet Explorer | 24/9/1999 | 16/6/2026 | Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5.1) | 36% | 💥 Exploit | Microsoft Internet Explorer | 10/9/1999 | 16/6/2026 | The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active Setup (setupctl.dll) ActiveX controls for Internet… | |
| Modificada | Alta (10) | 24% | 💥 Exploit | Microsoft Internet Explorer | 10/9/1999 | 16/6/2026 | Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites feature, aka the "ImportExportFavorites" vulnerability. | |
| Modificada | Media (5) | 43% | 💥 Exploit | Microsoft Internet Explorer | 1/9/1999 | 16/6/2026 | The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect. | |
| Modificada | Media (4) | 8.5% | — | Microsoft Internet Explorer | 1/9/1999 | 16/6/2026 | Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands. | |
| Modificada | Media (4) | 9.1% | 💥 Exploit | Microsoft Internet Explorer | 1/9/1999 | 16/6/2026 | The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | |
| Modificada | Media (5) | 7.7% | 💥 Exploit | Microsoft FrontpageMicrosoft Internet ExplorerMicrosoft Outlook ExpressQualcomm Eudora | 27/8/1999 | 16/6/2026 | Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell. | |
| Modificada | Media (4.6) | 2.7% | 💥 Exploit | Microsoft Internet Explorer | 25/8/1999 | 16/6/2026 | Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user… | |
| Modificada | Media (5.1) | 23% | 💥 Exploit | Microsoft Internet Explorer | 21/8/1999 | 16/6/2026 | The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. | |
| Modificada | Media (5.1) | 6.2% | — | Microsoft Internet Explorer | 27/5/1999 | 16/6/2026 | The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.6) | 10% | — | Microsoft Internet Explorer | 27/5/1999 | 16/6/2026 | Buffer overflow in Internet Explorer 5 allows remote attackers to execute commands via a malformed Favorites icon. |