Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3142▲ 563 respecto a la semana anterior
Críticas / altas1455▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 58% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 11/4/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption. | |
| Modificada | Media (5) | 2.4% | — | Internet KEY Exchange | 6/4/2006 | 16/6/2026 | The Internet Key Exchange version 1 (IKEv1) implementation (isakmp_agg.c) in the Shoichi Sakane KAME Project racoon, as used by NetBSD 1.6, 2.x before 20060119, certain FreeBSD releases, and possibly other distributions of BSD or Linux operating systems, when running in aggressive mode, allows remote attackers to… | |
| Modificada | Media (4.3) | 26% | 💥 Exploit | Microsoft Internet Explorer | 5/4/2006 | 16/6/2026 | Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading. NOTE: this… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Internet Solutions Professionals Site MAN | 2/4/2006 | 16/6/2026 | SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 24/3/2006 | 16/6/2026 | Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors. | |
| Modificada | Alta (9.3) | 68% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 23/3/2006 | 16/6/2026 | Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer. | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | Microsoft Internet Explorer | 7/3/2006 | 16/6/2026 | Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument. | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Internet Explorer | 21/2/2006 | 16/6/2026 | The scripting engine in Internet Explorer allows remote attackers to cause a denial of service (resource consumption) and possibly execute arbitrary code via a web page that contains a recurrent call to an infinite loop in Javascript or VBscript, which consumes the stack, as demonstrated by resetting the "location"… | |
| Modificada | Media (4) | 7.6% | — | Microsoft Internet Explorer | 19/2/2006 | 16/6/2026 | Microsoft Internet Explorer allows remote attackers to spoof a legitimate URL in the status bar and conduct a phishing attack via a web page with an anchor element with a legitimate "href" attribute, a form whose action points to a malicious URL, and an INPUT submit element that is modified to look like a legitimate… | |
| Modificada | Media (5) | 15% | — | Microsoft Internet Explorer | 8/2/2006 | 16/6/2026 | jscript.dll in Microsoft Internet Explorer 6.0 SP1 and earlier allows remote attackers to cause a denial of service (application crash) via a Shockwave Flash object that contains ActionScript code that calls VBScript, which in turn calls the Javascript document.write function, which triggers a null dereference. | |
| Modificada | Alta (7.5) | 2.2% | — | Egeinternet | 4/2/2006 | 16/6/2026 | Unspecified vulnerability in index.php in a certain application available from /v1/tr/portfoy.php on www.egeinternet.com allows remote attackers to execute arbitrary code via "evilcode" in the key parameter, possibly a PHP remote file include vulnerability in which the attack vector is a URL in the key parameter.… | |
| Modificada | Alta (7.5) | 20% | — | Microsoft IEMicrosoft Internet Explorer | 27/1/2006 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to bypass the Kill bit settings for dangerous ActiveX controls via unknown vectors involving crafted HTML, which can expose the browser to attacks that would otherwise be prevented by the Kill bit setting. NOTE: CERT/CC claims that MS05-054 fixes… | |
| Modificada | Media (5) | 3.0% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Personal ExpressF-secure Internet Gatekeeper | 21/1/2006 | 16/6/2026 | Multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allow remote attackers to hide arbitrary files and data via malformed (1) RAR and (2) ZIP… | |
| Modificada | Alta (7.5) | 5.8% | — | F-secure Anti-virusF-secure Internet SecurityF-secure Internet GatekeeperSolutions Based ON F-secure Personal Express | 21/1/2006 | 16/6/2026 | Buffer overflow in multiple F-Secure Anti-Virus products and versions for Windows and Linux, including Anti-Virus for Windows Servers 5.52 and earlier, Internet Security 2004, 2005 and 2006, and Anti-Virus for Linux Servers 4.64 and earlier, allows remote attackers to execute arbitrary code via crafted ZIP archives. | |
| Modificada | Media (5) | 2.8% | — | Eudora Internet Mail Server | 9/1/2006 | 16/6/2026 | Qualcomm Eudora Internet Mail Server (EIMS) before 3.2.8 allows remote attackers to cause a denial of service (crash) via (1) malformed NTLM authentication requests, or a malformed (2) Incoming Mail X or (3) Temporary Mail file. | |
| Modificada | Alta (7.1) | 9.2% | — | Microsoft Internet Explorer | 31/12/2005 | 16/6/2026 | The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | |
| Modificada | Alta (7.8) | 11% | — | Microsoft Internet Explorer | 31/12/2005 | 16/6/2026 | The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | |
| Modificada | Media (5.1) | 5.5% | — | Microsoft IEMicrosoft Internet Explorer | 31/12/2005 | 16/6/2026 | Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a user into performing a drag-and-drop action from certain objects, such as file objects within a folder view, then predicting the drag action, and re-focusing to a malicious… | |
| Modificada | Alta (7.1) | 12% | — | Microsoft Internet Explorer | 31/12/2005 | 16/6/2026 | The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | |
| Modificada | Alta (7.5) | 1.2% | — | RT Internet Solutions Webadmin | 31/12/2005 | 16/6/2026 | SQL injection vulnerability in RT Internet Solutions (RTIS) WebAdmin allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | |
| Modificada | Media (5) | 16% | 💥 Exploit | Microsoft IEMicrosoft Internet ExplorerMicrosoft Windows 2000Microsoft Windows 2003 Server+2 | 31/12/2005 | 16/6/2026 | Microsoft Internet Explorer 6.0 on Windows NT 4.0 SP6a, Windows 2000 SP4, Windows XP SP1, Windows XP SP2, and Windows Server 2003 SP1 allows remote attackers to cause a denial of service (client crash) via a certain combination of a malformed HTML file and a CSS file that triggers a null dereference, probably related… | |
| Modificada | Alta (7.5) | 11% | — | Microsoft IEMicrosoft Internet ExplorerCanon Network Camera Server Vb101 | 31/12/2005 | 16/6/2026 | Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method… | |
| Modificada | Alta (7.1) | 9.2% | — | Microsoft Internet Explorer | 31/12/2005 | 16/6/2026 | The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer. | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Explorer | 31/12/2005 | 16/6/2026 | Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX). | |
| Modificada | Media (4.3) | 1.2% | — | Esselbach Internet Solutions Esselbach Storyteller CMS | 21/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Esselbach Storyteller CMS 1.8 allows remote attackers to inject arbitrary web script or HTML via the query parameter, which is used by the Search field. |