Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3189▲ 608 respecto a la semana anterior
Críticas / altas1510▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2265 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)71%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services4/7/200116/6/2026
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that…
ModificadaAlta (7.2)0.36%—Cisco Content Services Switch 11050Cisco Content Services Switch 11150Cisco Content Services Switch 1180018/6/200116/6/2026
Cisco Content Services (CSS) switch products 11800 and earlier, aka Arrowpoint, allows local users to gain privileges by entering debug mode.
ModificadaMedia (5)37%—Microsoft Exchange ServerMicrosoft Internet Information Services2/6/200116/6/2026
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.
ModificadaMedia (5)68%💥 ExploitMicrosoft Internet Information Services2/6/200116/6/2026
IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.
ModificadaMedia (5)17%—Microsoft Windows Media Services12/2/200116/6/2026
Windows Media Unicast Service in Windows Media Services 4.0 and 4.1 does not properly shut down some types of connections, producing a memory leak that allows remote attackers to cause a denial of service via a series of severed connections, aka the "Severed Windows Media Server Connection" vulnerability.
ModificadaBaja (2.1)0.29%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.
ModificadaMedia (5)20%—Microsoft Internet Information ServerMicrosoft Internet Information Services12/2/200116/6/2026
FrontPage Server Extensions (FPSE) in IIS 4.0 and 5.0 allows remote attackers to cause a denial of service via a malformed form, aka the "Malformed Web Form Submission" vulnerability.
ModificadaMedia (5)28%—Microsoft Internet Information ServerMicrosoft Internet Information Services12/2/200116/6/2026
IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .HTR" vulnerability.
ModificadaBaja (2.1)0.52%—Cisco ArrowpointCisco Content Services Switch12/2/200116/6/2026
Directory traversal vulnerability in Arrowpoint (aka Cisco Content Services, or CSS) allows local unprivileged users to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)1.3%—Ptlink IRC ServicesPtlink Ircd9/1/200116/6/2026
PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.
ModificadaAlta (7.5)5.6%—Microsoft Internet Information ServerMicrosoft Internet Information Services9/1/200116/6/2026
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CVE-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same…
ModificadaMedia (5)44%💥 ExploitMicrosoft Internet Information Services19/12/200023/9/2026
Una mala configuración en IIS 5.0 con Index Server habilitado y la propiedad Index establecida permite a atacantes remotos listar directorios en la raíz web a través de una búsqueda de Web Distributed Authoring and Versioning (WebDAV).
ModificadaAlta (7.5)46%—Microsoft Internet Information ServerMicrosoft Internet Information Services19/12/200023/9/2026
Las páginas .ASP de IIS 4.0 y 5.0 envían la misma cookie de ID de sesión para sesiones web seguras e inseguras, lo que podría permitir a atacantes remotos secuestrar la sesión web segura del usuario si ese usuario se mueve a una sesión insegura, también conocida como la vulnerabilidad 'Session ID Cookie Marking'.
ModificadaAlta (7.5)69%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services19/12/200023/9/2026
IIS 5.0 permite a atacantes remotos ejecutar comandos arbitrarios a través de una solicitud malformada para un archivo ejecutable cuyo nombre se adjunta con comandos del sistema operativo, también conocida como la vulnerabilidad 'Web Server File Request Parsing'.
ModificadaAlta (7.5)63%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services19/12/200023/9/2026
IIS 4.0 y 5.0 permite a atacantes remotos leer documentos fuera de la raíz web, y posiblemente ejecutar comandos arbitrarios, a través de URLs malformadas que contienen caracteres codificados en UNICODE, también conocida como la vulnerabilidad de 'recorrido de carpetas del servidor web'.
ModificadaBaja (2.6)15%—Microsoft Windows Media Services14/11/200016/6/2026
Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.
ModificadaMedia (6.4)15%—Microsoft Internet Information ServerMicrosoft Internet Information Services20/10/200016/6/2026
IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" vulnerability.
ModificadaMedia (5)87%💥 ExploitMicrosoft Internet Information Services20/10/200016/6/2026
IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.
ModificadaAlta (7.5)10%—Microsoft FrontpageMicrosoft Internet Information ServerMicrosoft Internet Information Services20/10/200016/6/2026
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same…
ModificadaMedia (5)68%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services17/7/200016/6/2026
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
ModificadaMedia (5)25%—Microsoft Internet Information ServerMicrosoft Internet Information Services14/7/200016/6/2026
An administrative script from IIS 3.0, later included in IIS 4.0 and 5.0, allows remote attackers to cause a denial of service by accessing the script without a particular argument, aka the "Absent Directory Browser Argument" vulnerability.
ModificadaBaja (2.6)77%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services13/7/200016/6/2026
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.
ModificadaAlta (10)4.5%💥 ExploitNetscape Professional Services Ftpserver21/6/200016/6/2026
Netscape Professional Services FTP Server 1.3.6 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
ModificadaMedia (5)32%💥 ExploitMicrosoft Windows Media Services30/5/200016/6/2026
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.
ModificadaMedia (5)58%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services11/5/200016/6/2026
IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.