Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 17% | 💥 Exploit | Microsoft Internet Explorer | 31/12/2002 | 16/6/2026 | The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary script as other users and steal authentication information via cookies by injecting JavaScript into the URL, which is executed when the user hits the Back button. | |
| Modificada | Media (5) | 18% | 💥 Exploit | Microsoft Internet Explorer | 31/12/2002 | 16/6/2026 | Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight. | |
| Modificada | Media (5) | 34% | 💥 Exploit | Microsoft Exchange ServerMicrosoft Internet Information ServerMicrosoft Internet Information Services | 31/12/2002 | 16/6/2026 | The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-relaying rules and send spam or spoofed messages via encapsulated SMTP addresses, a similar vulnerability to CVE-1999-0682. | |
| Modificada | Media (5) | 16% | — | Microsoft Internet Information Services | 31/12/2002 | 16/6/2026 | Microsoft Internet Information Server (IIS) 5.1 allows remote attackers to view path information via a GET request to (1) /_vti_pvt/access.cnf, (2) /_vti_pvt/botinfs.cnf, (3) /_vti_pvt/bots.cnf, or (4) /_vti_pvt/linkinfo.cnf. | |
| Modificada | Media (5) | 12% | — | Microsoft Internet Explorer | 31/12/2002 | 16/6/2026 | Microsoft Internet Explorer 5.0, 5.01, and 5.5 allows remote attackers to monitor the contents of the clipboard via the getData method of the clipboardData object. | |
| Modificada | Alta (7.5) | 19% | — | Microsoft Internet Information Services | 31/12/2002 | 16/6/2026 | Off-by-one error in the CodeBrws.asp sample script in Microsoft IIS 5.0 allows remote attackers to view the source code for files with extensions containing with one additional character after .html, .htm, .asp, or .inc, such as .aspx files. | |
| Modificada | Media (6.4) | 1.2% | — | Open Source Internet Solutions | 31/12/2002 | 16/6/2026 | Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors. | |
| Modificada | Media (5) | 15% | — | Microsoft Internet Information Services | 31/12/2002 | 16/6/2026 | Microsoft Internet Information Server (IIS) 5.1 may allow remote attackers to view the contents of a Frontpage Server Extension (FPSE) file, as claimed using an HTTP request for colegal.htm that contains .. (dot dot) sequences. | |
| Modificada | Media (5) | 14% | — | Microsoft Internet Information Services | 31/12/2002 | 16/6/2026 | Microsoft IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with a Host header that contains a large number of "/" (forward slash) characters. | |
| Modificada | Media (5) | 13% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 31/12/2002 | 16/6/2026 | Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running. | |
| Modificada | Media (5) | 65% | 💥 Exploit | Microsoft Internet Information Services | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and determine the existence of arbitrary files via a hex-encoded "%c0%ae%c0%ae" string, which is the Unicode representation for ".." (dot dot). | |
| Modificada | Media (4.3) | 24% | 💥 Exploit | Macromedia ColdfusionMicrosoft Internet Information ServicesMicrosoft Windows 2000 | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in the missing template handler in Macromedia ColdFusion MX allows remote attackers to execute arbitrary script as other users by injecting script into the HTTP request for the name of a template, which is not filtered in the resulting 404 error message. | |
| Modificada | Media (4.3) | 13% | 💥 Exploit | Microsoft Internet Explorer | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ftp.htt in Internet Explorer 5.5 and 6.0, when running on Windows 2000 with "Enable folder view for FTP sites" and "Enable Web content in folders" selected, allows remote attackers to inject arbitrary web script or HTML via the hostname portion of an FTP URL. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 31/12/2002 | 16/6/2026 | Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object of type "text/html" with the DATA field that identifies the HTML document that contains the object, which may cause infinite recursion. | |
| Modificada | Alta (7.8) | 2.0% | — | Calisto Internet Talker | 31/12/2002 | 16/6/2026 | Calisto Internet Talker 0.04 and earlier allows remote attackers to cause a denial of service (hang) via a long request, possibly triggering a buffer overflow. | |
| Modificada | Media (6.4) | 9.5% | — | Microsoft Internet ExplorerOpera Software Opera WEB Browser | 31/12/2002 | 16/6/2026 | Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaScript (1) event.ctrlKey or (2) event.shiftKey onkeydown event contained in a webpage. NOTE: it was reported that the vendor has disputed the severity of this… | |
| Modificada | Alta (7.5) | 12% | — | Microsoft Internet Explorer | 18/12/2002 | 16/6/2026 | Internet Explorer 5.5 y 6.0 no realizan comprobaciones de seguridad completas en caché externa, lo que permite a atacantes remotos leer ficheros arbitrarios | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Microsoft IEMicrosoft Internet Explorer | 11/12/2002 | 16/6/2026 | Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods." | |
| Modificada | Media (6.4) | 12% | — | Microsoft Internet Explorer | 11/12/2002 | 16/6/2026 | Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading." | |
| Modificada | Media (6.8) | 15% | 💥 Exploit | Microsoft Internet Explorer | 11/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource. | |
| Modificada | Media (5) | 19% | — | Microsoft IEMicrosoft Internet Explorer | 11/12/2002 | 16/6/2026 | Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information… | |
| Modificada | Media (5) | 21% | — | Microsoft IEMicrosoft Internet Explorer | 11/12/2002 | 16/6/2026 | Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure." | |
| Modificada | Alta (7.5) | 76% | 💥 Exploit | Microsoft Data Access ComponentsMicrosoft IEMicrosoft Internet Explorer | 29/11/2002 | 16/6/2026 | Desbordamiento de búfer basado en la pila en el componente Remote Data Services (RDS) - Servicios de Datos Remotos de Microsoft Data Access Components (MDAC) 2.1 a 2.6, y en Internet Explorer 5.01 a 6.0 permite a atacantes remotos ejecutar código mediante una petición HTTP malformada al tocón (stub de datos). | |
| Modificada | Media (6.8) | 39% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/11/2002 | 16/6/2026 | Múltiples vulnerabilidades de scripting en sitios cruzados (XSS) en las páginas web de administració de Microsoft Internet Information Server (IIS) 4.0 a 5.1 permite a atacantes remotos ejecutar código HTML como otros usuarios. | |
| Modificada | Alta (7.5) | 9.7% | — | Microsoft Internet Information Services | 12/11/2002 | 16/6/2026 | Un error tipográfico en los permisos de acceso a fuentes de scripts en Internet Information Server (IIS) 5.0 no excluye adecuadamente ficheros .COM, lo que permite a atacantes con sólo permisos de escritura cargar ficheros .COM, también conocida como "Vulnerabilidad de Acceso a Fuente de Scripts" |