Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
209 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 22% | 💥 Exploit | Microsoft MSN Messenger | 31/12/2002 | 16/6/2026 | Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field. | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | AOL Instant Messenger | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers to conduct unauthorized activities, such as adding buddies and groups to a user's buddy list, via a URL with a META HTTP-EQUIV="refresh" tag to an aim: URL. | |
| Modificada | Media (5.8) | 1.2% | — | Yahoo Messenger | 31/12/2002 | 16/6/2026 | The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs via DNS spoofing. | |
| Modificada | Media (6.4) | 3.2% | — | Yahoo Messenger | 31/12/2002 | 16/6/2026 | Yahoo! Messenger before February 2002 allows remote attackers to add arbitrary users to another user's buddy list and possibly obtain sensitive information. | |
| Modificada | Media (5) | 1.9% | — | AOL Instant Messenger | 31/12/2002 | 16/6/2026 | Heap-based buffer overflow in the goim handler of AOL Instant Messenger (AIM) 4.4 through 4.8.2616 allows remote attackers to cause a denial of service (crash) via escaping of the screen name parameter, which triggers the overflow when the user selects "Get Info" on the buddy. | |
| Modificada | Alta (7.5) | 4.4% | — | Yahoo Messenger | 31/12/2002 | 16/6/2026 | Buffer overflow in Yahoo! Messenger before February 2002 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long set_buddygrp field. | |
| Modificada | Baja (2.6) | 6.9% | 💥 Exploit | AOL Instant Messenger | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8.2790 allows remote attackers to execute arbitrary programs by specifying the program in the href attribute of a link. | |
| Modificada | Media (5) | 3.7% | — | AOL Instant Messenger | 12/8/2002 | 16/6/2026 | AOL Instant Messenger (AIM) allows remote attackers to cause a denial of service (crash) via an "AddBuddy" link with the ScreenName parameter set to a large number of comma-separated values, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 12% | — | Microsoft MSN Messenger | 12/8/2002 | 16/6/2026 | MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users. | |
| Modificada | Alta (7.5) | 3.9% | — | Yahoo Messenger | 26/7/2002 | 16/6/2026 | Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary script as other users via the addview parameter of a ymsgr URI. | |
| Modificada | Media (4.6) | 4.9% | 💥 Exploit | Yahoo Messenger | 26/7/2002 | 16/6/2026 | Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend. | |
| Modificada | Media (5) | 3.3% | — | Yahoo Messenger | 25/6/2002 | 16/6/2026 | Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks. | |
| Modificada | Alta (7.5) | 7.0% | — | Yahoo Messenger | 25/6/2002 | 16/6/2026 | Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field. | |
| Modificada | Alta (7.5) | 1.6% | — | Yahoo Messenger | 25/6/2002 | 16/6/2026 | Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing. | |
| Modificada | Alta (7.5) | 1.6% | — | AOL Instant Messenger | 18/6/2002 | 16/6/2026 | AOL Instant Messenger (AIM) allows remote attackers to steal files that are being transferred to other clients by connecting to port 4443 (Direct Connection) or port 5190 (file transfer) before the intended user. | |
| Modificada | Media (5) | 12% | 💥 Exploit | AOL Instant Messenger | 18/6/2002 | 16/6/2026 | Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create arbitrary files and execute commands via a Direct Connection with an IMG tag with a SRC attribute that specifies the target filename. | |
| Modificada | Alta (7.5) | 24% | — | Microsoft MSN Chat ControlMicrosoft MSN MessengerMicrosoft MSN Messenger Service FOR Exchange | 29/5/2002 | 16/6/2026 | Buffer overflow in Microsoft MSN Chat ActiveX Control, as used in MSN Messenger 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6, allows remote attackers to execute arbitrary code via a long ResDLL parameter in the MSNChat OCX. | |
| Modificada | Alta (7.5) | 3.8% | — | AOL Instant Messenger | 29/5/2002 | 16/6/2026 | Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711. | |
| Modificada | Media (5) | 20% | — | Microsoft MSN Messenger | 16/5/2002 | 16/6/2026 | Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites). | |
| Modificada | Alta (7.5) | 1.7% | — | AOL Instant Messenger | 8/4/2002 | 16/6/2026 | AOL Instant Messenger (AIM) 4.7.2480 adds free.aol.com to the Trusted Sites Zone in Internet Explorer without user approval, which could allow code from free.aol.com to bypass intended access restrictions. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | AOL Instant Messenger | 31/1/2002 | 16/6/2026 | Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame). | |
| Modificada | Media (5) | 6.0% | 💥 Exploit | Internet Software Solutions AIR Messenger LAN Server | 18/10/2001 | 16/6/2026 | Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header. | |
| Modificada | Media (5) | 1.8% | — | Internet Software Solutions AIR Messenger LAN Server | 18/10/2001 | 16/6/2026 | Directory traversal in Webpaging interface in Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows allows remote attackers to read arbitrary files via a .. (dot dot) attack. | |
| Modificada | Media (5) | 1.1% | — | Internet Software Solutions AIR Messenger LAN Server | 18/10/2001 | 16/6/2026 | Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 stores user passwords in plaintext in the pUser.Dat file. | |
| Modificada | Media (5) | 2.2% | — | AOL Instant Messenger | 6/10/2001 | 16/6/2026 | AOL Instant Messenger (AIM) 4.7 allows remote attackers to cause a denial of service (application crash) via a malformed WAV file. |