Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 685 respecto a la semana anterior
Críticas / altas1521▲ 128 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | 💥 Exploit | Scheduling Management.com Time Tracking Software | 15/2/2006 | 16/6/2026 | edituser.php in TTS Time Tracking Software 3.0 does not verify that the name and password are correct, which allows remote attackers to overwrite arbitrary data belonging to any account. | |
| Modificada | Alta (7.5) | 1.3% | — | Idea Development ID OY Timecan CMS | 7/1/2006 | 16/6/2026 | SQL injection vulnerability in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the viewID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot be determined if… | |
| Modificada | Alta (7.5) | 1.3% | — | Idea Development ID OY Timecan CMS | 7/1/2006 | 16/6/2026 | SQL injection vulnerability in mcl_login.asp in Timecan CMS allows remote attackers to execute arbitrary SQL commands via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Due to the unavailability of the original source, it cannot… | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (4.3) | 0.84% | — | Ignite Realtime Openfire | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.3.0 Beta 2 allows remote attackers to inject arbitrary web script or HTML via Javascript events in the username parameter, a different vulnerability than CVE-2005-4876. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (7.5) | 8.0% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files. | |
| Modificada | Alta (7.5) | 3.2% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files. | |
| Modificada | Alta (7.5) | 4.1% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Apple Quicktime | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field. | |
| Modificada | Alta (7.5) | 4.0% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file. | |
| Modificada | Media (4.3) | 0.84% | — | Ignite Realtime Openfire | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the login form (login.jsp) of the admin console in Openfire (formerly Wildfire) 2.2.2, and possibly other versions before 2.3.0 Beta 2, allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-4877. | |
| Modificada | Alta (7.5) | 7.3% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags. | |
| Modificada | Alta (7.5) | 8.6% | — | Apple Quicktime | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Alta (7.5) | 8.8% | — | Apple ItunesApple Quicktime | 8/12/2005 | 16/6/2026 | Multiple heap-based buffer overflows in QuickTime.qts in Apple QuickTime Player 7.0.3 and iTunes 6.0.1 (3) and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a .mov file with (1) a Movie Resource atom with a large size value, or (2) an stsd atom with a modified… | |
| Modificada | Media (5.1) | 2.1% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes." | |
| Modificada | Media (5.1) | 4.2% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion. | |
| Modificada | Baja (2.6) | 1.8% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference. | |
| Modificada | Media (5.1) | 2.1% | — | Apple Quicktime | 5/11/2005 | 16/6/2026 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string. | |
| Modificada | Alta (7.5) | 4.7% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 26/10/2005 | 16/6/2026 | The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Indiatimes Messenger | 8/9/2005 | 16/6/2026 | Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long group name argument to the RenameGroup function in the MMClient.MunduMessenger.1 ActiveX object. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | LS Games WAR Times | 24/5/2005 | 16/6/2026 | Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. | |
| Modificada | Media (5) | 2.0% | — | Apple Quicktime | 12/5/2005 | 16/6/2026 | Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | |
| Modificada | Media (4.6) | 0.36% | — | Mandrakesoft Mandrake Lam-runtime | 3/5/2005 | 16/6/2026 | The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges. |