Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2526 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)36%—Microsoft Internet Information Services12/11/200216/6/2026
IIS 5.0 Y 5.1 permiten a atacantes remotso causar una denegación de servicio (caída) mediante peticiones WebDAV malformadas que hacen que sea asignada mucha memoria.
ModificadaAlta (7.5)24%—Microsoft Internet Information ServerMicrosoft Internet Information Services12/11/200216/6/2026
Vulnerabilidad desconocida en el proceso de anfitrión (dllhost.exe) en Microsoft Internet Information Server (IIS) 4.0 a 5.1 permite a atacantes remotos ganar privilegios ejecutando una aplicación fuera de proceso que adquiere privilegios de LocalSystem, también conocida como "Elevación de Privilegios Fuera de…
ModificadaAlta (7.5)50%💥 ExploitMicrosoft Internet Explorer28/10/200216/6/2026
Vulnerabilidad de scripts en marcos cruzados en el control WebBrowser usado en Internet Explorer 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario, leer ficheros arbitrarios, y llevar a cabo otras actividades no autorizadas mediante código que accede a la propiedad Document, lo que evita las…
ModificadaMedia (6.8)16%💥 ExploitMicrosoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+54/10/200216/6/2026
Las APIs (Application Programming Interface) CertGetCertificateChain CertVerifyCertificateChainPolicy WinVerifyTrust en la CriptoAPI de productos de Microsoft, incluyendo Microsoft Windows 98 a XP, Office para Mac, Internet Explorer para Mac, y Outlook Express para Mac, no verifican adecuadamente las restricciones…
ModificadaMedia (5)48%💥 ExploitMicrosoft Internet Explorer24/9/200216/6/2026
La capacidad de isla de datos <script> (legacy - legado - para compatibilidad con anteriores versiones) en XML en Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos leer ficheros XML de su elección, y parte de otros ficheros, mediante una URL cuyo atributo "src" redirige a un fichero local.
ModificadaAlta (7.5)27%💥 ExploitMicrosoft Internet Explorer24/9/200216/6/2026
El componente de Carpetas Web en Internet Explorer 5.5 y 6.0 escribe un mensaje de error en una localización conocida en una carpeta temporal, lo que permite a atacantes remotos ejecutar código arbitrario inyectándolo en el mensaje de error, y refiriendose al mensaje de error mediante una URL mhtml:
ModificadaAlta (7.5)3.2%—ISS Internet Scanner24/9/200216/6/2026
Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response.
ModificadaMedia (6.4)14%💥 ExploitMicrosoft Internet Explorer24/9/200216/6/2026
Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.
ModificadaAlta (7.5)13%—Microsoft Internet Explorer24/9/200216/6/2026
Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing."
ModificadaAlta (7.5)14%—Microsoft Internet Explorer24/9/200216/6/2026
Microsoft Internet Explorer 5.01 y 5.5 permite a atacantes remotos ejecutar secuencias de comandos en la zona del PC local mediante una URL que hace referencia un ficherio de recurso local HTML, una variante de la vulnerabilidad "Secuencias de comandos en sitios cruzados en recurso HTML local (Cross-Site Scripting in…
ModificadaAlta (7.5)23%💥 ExploitMicrosoft Internet Explorer24/9/200216/6/2026
Desbordamiento de búfer en el control ActiveX antiguo usado para mostrar texto especialmente formateado en Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario. También conocida como "Desbordamiento de búfer en control ActiveX antiguo de formato de texto" (Buffer Overrun…
ModificadaAlta (7.5)15%💥 ExploitMicrosoft Internet Explorer24/9/200216/6/2026
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."
ModificadaBaja (2.6)14%💥 ExploitGoogle ToolbarMicrosoft Internet Explorer15/8/200216/6/2026
The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function.
ModificadaMedia (5)16%—Microsoft Internet Explorer12/8/200216/6/2026
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.
ModificadaMedia (5)37%💥 ExploitMicrosoft Internet Information ServerMicrosoft Internet Information Services12/8/200216/6/2026
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP…
ModificadaAlta (7.5)9.9%—Microsoft Internet Explorer12/8/200216/6/2026
Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature.
ModificadaAlta (7.5)3.7%—Microsoft Internet ExplorerMozillaNetscape Navigator12/8/200216/6/2026
The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted…
ModificadaBaja (2.6)51%—Microsoft Internet Information Services12/8/200216/6/2026
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method,…
ModificadaMedia (5)24%💥 ExploitMicrosoft Internet Explorer12/8/200216/6/2026
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.
ModificadaAlta (7.5)3.3%—Symantec Norton Internet SecuritySymantec Norton Personal Firewall26/7/200216/6/2026
Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request.
ModificadaAlta (7.5)54%💥 ExploitMicrosoft Internet ExplorerMicrosoft ISA ServerMicrosoft Proxy ServerUniversity OF Minnesota Gopher3/7/200216/6/2026
Desbordamiento de búfer en el cliente gopher de Microsoft Internet Explorer 5.1 a la 6.0, Proxy Server 2.0, o ISA Server 2000 permite a atacantes remotos la ejecución de código arbitrario mediante una URL gopher:// que redirige al usuario a un servidor gopher real o simulado que envía una respuesta larga.
ModificadaAlta (7.5)31%—Microsoft Internet Information ServerMicrosoft Internet Information Services3/7/200216/6/2026
Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."
ModificadaAlta (7.5)24%—Microsoft Internet Explorer29/5/200216/6/2026
Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario con menos restricciones de seguridad mediante una página Web malformada que requiere conectividad NetBIOS. También conocida como "Vulnerabilidad de engaño de zona mediante una página Web malformada".
ModificadaAlta (7.5)33%💥 ExploitMicrosoft Internet Explorer29/5/200216/6/2026
(repetida de CAN-2002-0193)
ModificadaAlta (7.5)11%—Microsoft Internet Explorer29/5/200216/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en Internet Explorer 6 y anteriores permite que atacante remotos ejecuten código arbitrario por medio de un formulario HTML extendido, cuya salida del servidor remoto no se ha aclarado adecuadamente.