Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

209 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)22%💥 ExploitMicrosoft MSN Messenger31/12/200216/6/2026
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
ModificadaMedia (5)2.4%💥 ExploitAOL Instant Messenger31/12/200216/6/2026
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL.
ModificadaMedia (5.8)1.2%—Yahoo Messenger31/12/200216/6/2026
The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing.
ModificadaMedia (6.4)3.2%—Yahoo Messenger31/12/200216/6/2026
Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information.
ModificadaMedia (5)1.9%—AOL Instant Messenger31/12/200216/6/2026
Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy.
ModificadaAlta (7.5)4.4%—Yahoo Messenger31/12/200216/6/2026
Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field.
ModificadaBaja (2.6)6.9%💥 ExploitAOL Instant Messenger31/12/200216/6/2026
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link.
ModificadaMedia (5)3.7%—AOL Instant Messenger12/8/200216/6/2026
AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow.
ModificadaMedia (5)12%—Microsoft MSN Messenger12/8/200216/6/2026
MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.
ModificadaAlta (7.5)3.9%—Yahoo Messenger26/7/200216/6/2026
Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI.
ModificadaMedia (4.6)4.9%💥 ExploitYahoo Messenger26/7/200216/6/2026
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.
ModificadaMedia (5)3.3%—Yahoo Messenger25/6/200216/6/2026
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.
ModificadaAlta (7.5)7.0%—Yahoo Messenger25/6/200216/6/2026
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.
ModificadaAlta (7.5)1.6%—Yahoo Messenger25/6/200216/6/2026
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.
ModificadaAlta (7.5)1.6%—AOL Instant Messenger18/6/200216/6/2026
AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user.
ModificadaMedia (5)12%💥 ExploitAOL Instant Messenger18/6/200216/6/2026
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename.
ModificadaAlta (7.5)24%—Microsoft MSN Chat ControlMicrosoft MSN MessengerMicrosoft MSN Messenger Service FOR Exchange29/5/200216/6/2026
Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX.
ModificadaAlta (7.5)3.8%—AOL Instant Messenger29/5/200216/6/2026
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.
ModificadaMedia (5)20%—Microsoft MSN Messenger16/5/200216/6/2026
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).
ModificadaAlta (7.5)1.7%—AOL Instant Messenger8/4/200216/6/2026
AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions.
ModificadaAlta (10)16%💥 ExploitAOL Instant Messenger31/1/200216/6/2026
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).
ModificadaMedia (5)6.0%💥 ExploitInternet Software Solutions AIR Messenger LAN Server18/10/200116/6/2026
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header.
ModificadaMedia (5)1.8%—Internet Software Solutions AIR Messenger LAN Server18/10/200116/6/2026
Directory traversal in Webpaging interface in Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)1.1%—Internet Software Solutions AIR Messenger LAN Server18/10/200116/6/2026
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 stores user passwords in plaintext in the pUser.Dat file.
ModificadaMedia (5)2.2%—AOL Instant Messenger6/10/200116/6/2026
AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file.
Orbitaley — Vulnerabilidades