Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 566 respecto a la semana anterior
Críticas / altas1456▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 16% | — | Microsoft Internet Explorer | 23/6/2006 | 16/6/2026 | Versión no especificada de Internet Explorer permite a atacantes remotos causar una denegación de servicio (caída) a través de un IFRAME con una etiqueta src que contiene "File://" seguido por un caracter de 8 bits. NOTA: algunos de estos detalles han sido obtenidos de terceras partes. | |
| Modificada | Media (5) | 7.2% | 💥 Exploit | Kaspersky Anti-virusKaspersky Internet Security | 19/6/2006 | 16/6/2026 | klif.sys en Kaspersky Internet Security v6.0 y v7.0, Kaspersky Anti-Virus (KAV) v6.0 y v7.0, KAV v6.0 para Windows Workstations, y KAV v6.0 para Windows Servers no validan de forma adecuada ciertos parámetros de llamadas al sistema "enganchadas" sobre (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4)… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Internet Explorer | 13/6/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address… | |
| Modificada | Media (6.8) | 35% | — | Microsoft IEMicrosoft Internet ExplorerMicrosoft Windows 2003 ServerMicrosoft Windows XP | 13/6/2006 | 16/6/2026 | Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption. | |
| Modificada | Alta (9.3) | 38% | — | Microsoft IEMicrosoft Internet Explorer | 13/6/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2)… | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Microsoft Internet Explorer | 13/6/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the… | |
| Modificada | Alta (10) | 49% | — | Microsoft Internet Explorer | 13/6/2006 | 16/6/2026 | Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability." | |
| Modificada | Alta (7.6) | 20% | — | Microsoft IEMicrosoft Internet Explorer | 13/6/2006 | 16/6/2026 | Vulnerabilidad no especificada en Microsoft Internet Explorer 5.01 SP4 y 6 SP1 y anteriores permite a atacantes asistidos por el usuario ejecutar código de forma arbitraria a través de una página web manipulada que dispara una corrupción de memoria cuando se guarda como un archivo multipart HTML (.mht) | |
| Modificada | Media (6.5) | 3.8% | 💥 Exploit | Estsoft Internetdisk | 7/6/2006 | 16/6/2026 | Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory. | |
| Modificada | Alta (7.6) | 5.7% | — | F-secure Anti-virusF-secure Internet Gatekeeper | 6/6/2006 | 16/6/2026 | Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors. NOTE: By default, the connections are only allowed from… | |
| Modificada | Baja (2.6) | 48% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 2/6/2006 | 16/6/2026 | Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file. | |
| Modificada | Media (6.8) | 1.6% | — | Interquest Internet Services Realty PRO ONE | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One allow remote attackers to inject arbitrary web script or HTML via the (1) listingid parameter to (a) images.php, (b) index_other.php, or (c) request_info.php; (2) propertyid parameter to (d) searchlookup.php, (3) id parameter to (e) images.php, or… | |
| Modificada | Media (5) | 2.8% | — | Internet KEY Exchange | 10/5/2006 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked daemon crash) via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. | |
| Modificada | Alta (9.3) | 33% | — | Microsoft Internet Explorer | 5/5/2006 | 16/6/2026 | Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992. | |
| Modificada | Media (5.1) | 23% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 29/4/2006 | 16/6/2026 | Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race… | |
| Modificada | Media (5) | 13% | — | Microsoft Internet Explorer | 26/4/2006 | 16/6/2026 | Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft Outlook with an arbitrary filename as an… | |
| Modificada | Baja (2.6) | 40% | 💥 Exploit | Microsoft Internet Explorer | 25/4/2006 | 16/6/2026 | mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that… | |
| Modificada | Alta (7.5) | 3.9% | 💥 Exploit | Thomas Voecking Internet Photoshow | 20/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. | |
| Modificada | Media (6.8) | 0.39% | — | Symantec LiveupdateSymantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton Personal Firewall+2 | 19/4/2006 | 16/6/2026 | Untrusted search path vulnerability in unspecified components in Symantec LiveUpdate for Macintosh 3.0.0 through 3.5.0 do not set the execution path, which allows local users to gain privileges via a Trojan horse program. | |
| Modificada | Alta (10) | 62% | 💥 Exploit | Microsoft Internet Explorer | 11/4/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code. | |
| Modificada | Media (4) | 32% | 💥 Exploit | Microsoft Internet Explorer | 11/4/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site. | |
| Modificada | Alta (10) | 62% | 💥 Exploit | Microsoft Internet Explorer | 11/4/2006 | 16/6/2026 | Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability." | |
| Modificada | Baja (2.6) | 32% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb101 | 11/4/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is… | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb101 | 11/4/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption. | |
| Modificada | Alta (7.5) | 58% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb101 | 11/4/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption. |