Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)18%💥 ExploitAdobe Acrobat ReaderMozilla FirefoxNetscape NavigatorOpera Browser10/3/200716/6/2026
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followed by many %n sequences, a different vulnerability than CVE-2006-6027…
ModificadaMedia (5)2.0%—Mozilla FirefoxNetscape Navigator24/11/200616/6/2026
The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matches the web site for which the user stored a password, which allows…
ModificadaBaja (3.6)7.6%💥 ExploitNetscape Portable Runtime APISUN Solaris12/10/200616/6/2026
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.
ModificadaAlta (7.6)15%💥 ExploitK-meleon Project K-meleonMozilla FirefoxNetscape Navigator21/8/200616/6/2026
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency…
ModificadaMedia (4)9.8%💥 ExploitMozilla FirefoxMozilla SuiteMozilla SeamonkeyNetscape Navigator7/6/200616/6/2026
Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the…
ModificadaMedia (5)1.4%—Sitescape Forum31/5/200616/6/2026
Dispatch.cgi/_user/uservCard/ in SiteScape Forum 7.2 and possibly earlier generates different responses in a way that allows remote attackers to enumerate valid usernames.
ModificadaMedia (5)1.4%—Sitescape Forum31/5/200616/6/2026
SiteScape Forum 7.2 and possibly earlier stores the avf.rc configuraiton file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive path information.
ModificadaMedia (4.3)1.7%—Mozilla FirefoxMozilla SuiteNetscape Navigator26/5/200616/6/2026
Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1, and possibly other versions and products, allows remote user-assisted attackers to obtain information such as the installation path by causing exceptions to be thrown and checking the message…
ModificadaMedia (5.1)2.6%—K-meleon Project K-meleonMozilla FirefoxNetscape Navigator20/4/200616/6/2026
Mozilla Firefox 1.5.0.2 and possibly other versions before 1.5.0.4, Netscape 8.1, 8.0.4, and 7.2, and K-Meleon 0.9.13 allows user-assisted remote attackers to open local files via a web page with an IMG element containing a SRC attribute with a non-image file:// URL, then tricking the user into selecting View Image…
ModificadaMedia (5)1.9%—Globalscape Secure FTP Server11/4/200616/6/2026
Unspecified vulnerability in GlobalSCAPE Secure FTP Server before 3.1.4 Build 01.10.2006 allows attackers to cause a denial of service (application crash) via a "custom command" with a long argument.
ModificadaMedia (5)13%💥 ExploitK-meleon Project K-meleonMozilla FirefoxMozilla SuiteNetscape Navigator9/12/200516/6/2026
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports,…
ModificadaBaja (2.1)0.35%—Inkscape29/11/200516/6/2026
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
ModificadaMedia (5.1)13%💥 ExploitInkscape22/11/200516/6/2026
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute arbitrary code via a SVG file with long CSS style property values.
ModificadaAlta (10)61%💥 ExploitGlobalscape Secure FTP Server3/5/200516/6/2026
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.
ModificadaAlta (7.5)2.3%—Mozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."
ModificadaAlta (7.5)2.5%—Mozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka…
ModificadaMedia (5)10%💥 ExploitMozilla FirefoxMozillaNetscape Navigator2/5/200516/6/2026
The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
ModificadaAlta (7.5)1.7%—Netscape Navigator10/1/200516/6/2026
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.
ModificadaMedia (5)1.1%—Globalscape Cuteftp10/1/200516/6/2026
Buffer overflow in CuteFTP Professional 6.0, and possibly other versions, allows remote FTP servers to cause a denial of service (application crash) via large replies to FTP commands.
ModificadaBaja (2.6)1.6%—Mozilla FirefoxMozillaNetscape Navigator31/12/200416/6/2026
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.
ModificadaAlta (10)8.0%—Mozilla FirefoxMozillaMozilla ThunderbirdNetscape Navigator+631/12/200416/6/2026
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
ModificadaAlta (7.5)23%—Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+631/12/200416/6/2026
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.
ModificadaMedia (5)3.8%💥 ExploitGlobalscape Secure FTP Server31/12/200416/6/2026
Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service (crash) via a SITE command with a long argument.
ModificadaAlta (10)8.9%—Netscape Directory Server31/12/200416/6/2026
Buffer overflow in the LDAP component for Netscape Directory Server (NDS) 3.6 on HP-UX and other operating systems allows remote attackers to execute arbitrary code.
ModificadaAlta (10)2.0%—IBM Cloudscape23/11/200416/6/2026
IBM Cloudscape 5.1 running jdk 1.4.2_03 allows remote attackers to execute arbitrary programs or cause a denial of service via certain SQL code, possibly due to a SQL injection vulnerability.
Orbitaley — Vulnerabilidades