Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)17%💥 ExploitMicrosoft Internet Explorer31/12/200216/6/2026
The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button.
ModificadaMedia (5)18%💥 ExploitMicrosoft Internet Explorer31/12/200216/6/2026
Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.
ModificadaMedia (5)34%💥 ExploitMicrosoft Exchange ServerMicrosoft Internet Information ServerMicrosoft Internet Information Services31/12/200216/6/2026
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682.
ModificadaMedia (5)16%—Microsoft Internet Information Services31/12/200216/6/2026
Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf.
ModificadaMedia (5)12%—Microsoft Internet Explorer31/12/200216/6/2026
Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object.
ModificadaAlta (7.5)19%—Microsoft Internet Information Services31/12/200216/6/2026
Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files.
ModificadaMedia (6.4)1.2%—Open Source Internet Solutions31/12/200216/6/2026
Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.
ModificadaMedia (5)15%—Microsoft Internet Information Services31/12/200216/6/2026
Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences.
ModificadaMedia (5)14%—Microsoft Internet Information Services31/12/200216/6/2026
Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters.
ModificadaMedia (5)13%—Microsoft Internet Information ServerMicrosoft Internet Information Services31/12/200216/6/2026
Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
ModificadaMedia (5)65%💥 ExploitMicrosoft Internet Information Services31/12/200216/6/2026
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot).
ModificadaMedia (4.3)24%💥 ExploitMacromedia ColdfusionMicrosoft Internet Information ServicesMicrosoft Windows 200031/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message.
ModificadaMedia (4.3)13%💥 ExploitMicrosoft Internet Explorer31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL.
ModificadaMedia (5)19%💥 ExploitMicrosoft IEMicrosoft Internet Explorer31/12/200216/6/2026
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion.
ModificadaAlta (7.8)2.0%—Calisto Internet Talker31/12/200216/6/2026
Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow.
ModificadaMedia (6.4)9.5%—Microsoft Internet ExplorerOpera Software Opera WEB Browser31/12/200216/6/2026
Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this…
ModificadaAlta (7.5)12%—Microsoft Internet Explorer18/12/200216/6/2026
Internet Explorer 5.5 y 6.0 no realizan comprobaciones de seguridad completas en caché externa, lo que permite a atacantes remotos leer ficheros arbitrarios
ModificadaAlta (7.5)54%💥 ExploitMicrosoft IEMicrosoft Internet Explorer11/12/200216/6/2026
Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."
ModificadaMedia (6.4)12%—Microsoft Internet Explorer11/12/200216/6/2026
Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."
ModificadaMedia (6.8)15%💥 ExploitMicrosoft Internet Explorer11/12/200216/6/2026
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.
ModificadaMedia (5)19%—Microsoft IEMicrosoft Internet Explorer11/12/200216/6/2026
Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information…
ModificadaMedia (5)21%—Microsoft IEMicrosoft Internet Explorer11/12/200216/6/2026
Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."
ModificadaAlta (7.5)76%💥 ExploitMicrosoft Data Access ComponentsMicrosoft IEMicrosoft Internet Explorer29/11/200216/6/2026
Desbordamiento de búfer basado en la pila en el componente Remote Data Services (RDS) - Servicios de Datos Remotos de Microsoft Data Access Components (MDAC) 2.1 a 2.6, y en Internet Explorer 5.01 a 6.0 permite a atacantes remotos ejecutar código mediante una petición HTTP malformada al tocón (stub de datos).
ModificadaMedia (6.8)39%—Microsoft Internet Information ServerMicrosoft Internet Information Services12/11/200216/6/2026
Múltiples vulnerabilidades de scripting en sitios cruzados (XSS) en las páginas web de administració de Microsoft Internet Information Server (IIS) 4.0 a 5.1 permite a atacantes remotos ejecutar código HTML como otros usuarios.
ModificadaAlta (7.5)9.7%—Microsoft Internet Information Services12/11/200216/6/2026
Un error tipográfico en los permisos de acceso a fuentes de scripts en Internet Information Server (IIS) 5.0 no excluye adecuadamente ficheros .COM, lo que permite a atacantes con sólo permisos de escritura cargar ficheros .COM, también conocida como "Vulnerabilidad de Acceso a Fuente de Scripts"