Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
228 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.0% | — | RIM Blackberry Enterprise ServerRIM Blackberry Professional Software | 28/7/2009 | 16/6/2026 | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or… | |
| Modificada | Alta (7.1) | 1.6% | — | RIM Blackberry 8800 | 22/7/2009 | 16/6/2026 | The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption and browser crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692. | |
| Modificada | Alta (9.3) | 18% | 💥 Exploit | Strawberry | 22/5/2009 | 16/6/2026 | Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to example/index.php. NOTE: this was originally reported as an issue affecting the do parameter, but traversal with that parameter… | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | RIM Blackberry Enterprise Server | 22/4/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2)… | |
| Modificada | Alta (9.3) | 19% | — | Research IN Motion Limited Blackberry Application WEB Loader | 10/2/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method. | |
| Modificada | Alta (9.3) | 4.9% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 21/1/2009 | 16/6/2026 | The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to… | |
| Modificada | Alta (9.3) | 5.5% | — | Research IN Motion Limited Blackberry Enterprise ServerResearch IN Motion Limited Blackberry Professional SoftwareResearch IN Motion Limited Blackberry Unite | 20/1/2009 | 16/6/2026 | Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via… | |
| Modificada | Alta (9.3) | 6.9% | — | Blackberry Enterprise ServerBlackberry UniteRIM Blackberry Enterprise ServerRIM Blackberry Enterprise Server FOR Domino+3 | 21/7/2008 | 16/6/2026 | Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment. | |
| Modificada | Alta (9.3) | 5.9% | 💥 Exploit | Blackberry QNX Momentics | 7/7/2008 | 16/6/2026 | Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/. | |
| Modificada | Alta (10) | 1.4% | — | RIM Blackberry Enterprise Server | 28/6/2007 | 16/6/2026 | Research in Motion BlackBerry Enterprise Server 4.0 through 4.1 has a default configuration that permits installation of arbitrary third-party applications on BlackBerry devices, which might facilitate loading of malware. | |
| Modificada | Media (4.3) | 1.9% | — | RIM Blackberry SoftwareRIM Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 with 4.0 SP1 Bundle 83 allows remote attackers to cause a denial of service (blocked call reception) via a malformed SIP invite message, possibly related to multiple format string specifiers in the From field, a spoofed source IP address, and limitations of the function stack… | |
| Modificada | Baja (2.3) | 0.60% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered. | |
| Modificada | Baja (2.3) | 0.67% | — | Research IN Motion Limited Blackberry 7270 | 27/6/2007 | 16/6/2026 | Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header. | |
| Modificada | Media (4.3) | 1.7% | — | RIM Blackberry 8100RIM BlackberryRIM Blackberry Browser | 14/3/2007 | 16/6/2026 | The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page. | |
| Modificada | Media (5) | 1.5% | — | RIM Blackberry Enterprise Server | 25/10/2006 | 16/6/2026 | Research in Motion (RIM) BlackBerry Enterprise Server 4.1 SP2 before Hotfix 1 for IBM Lotus Domino might allow attackers with meeting organizer privileges to cause a denial of service (application hang) via a deleted recurrent meeting instance when changing the attendee's calendar meeting time. | |
| Modificada | Media (5) | 2.0% | — | Bitberry Software Bitzipper | 22/5/2006 | 16/6/2026 | Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitrary directories via a .. (dot dot) in the filename of a file that is stored in a (1) RAR (.rar), (2) TAR (.tar), (3) ZIP (.zip), (4) GZ (.gz), or (5) JAR (.jar) archive. | |
| Modificada | Media (5.1) | 2.7% | — | RIM Blackberry Enterprise Server | 18/2/2006 | 16/6/2026 | Buffer overflow in BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server 2.2 and 4.0 before SP3 Hotfix 4 for IBM Lotus Domino, 3.6 before SP7 and 5.0 before SP3 Hotfix 3 for Microsoft Exchangem, and 4.0 for Novell GroupWise before SP3 Hotfix 1 might allow user-assisted remote attackers… | |
| Modificada | Media (5) | 2.5% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 3.9% | — | RIM Blackberry Enterprise ServerRIM Blackberry Router | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets. | |
| Modificada | Alta (7.5) | 3.2% | — | RIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Buffer overflow in the decompression algorithm in Research in Motion BlackBerry Enterprise Server 4.0 SP1 and earlier before 20050607 might allow remote attackers to execute arbitrary code via certain data packets. | |
| Modificada | Baja (2.6) | 2.6% | — | RIM Blackberry Desktop ManagerRIM Blackberry Device SoftwareRIM Blackberry | 31/12/2005 | 16/6/2026 | Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file with a long application name and vendor string, which prevents a browser dialog from being properly dismissed. | |
| Modificada | Alta (7.5) | 2.2% | — | RIM Blackberry Attachment ServiceRIM Blackberry Enterprise Server | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Research in Motion (RIM) BlackBerry Attachment Service allows remote attackers to cause a denial of service (hang) via an e-mail attachment with a crafted TIFF file. | |
| Modificada | Media (5.1) | 1.7% | — | Mcafee AntivirusAIPowerzipAIWinzipAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of McAfee Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | ClamavAIRarlab WinrarAIPowerzio PowerzipAIPkware WinzipAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of ClamAV Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 1.7% | — | PowzipAIWinzipAIPanda AntivirusAIRarlab WinrarAI+1 | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… |