Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2526 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 36% | — | Microsoft Internet Information Services | 12/11/2002 | 16/6/2026 | IIS 5.0 Y 5.1 permiten a atacantes remotso causar una denegación de servicio (caída) mediante peticiones WebDAV malformadas que hacen que sea asignada mucha memoria. | |
| Modificada | Alta (7.5) | 24% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/11/2002 | 16/6/2026 | Vulnerabilidad desconocida en el proceso de anfitrión (dllhost.exe) en Microsoft Internet Information Server (IIS) 4.0 a 5.1 permite a atacantes remotos ganar privilegios ejecutando una aplicación fuera de proceso que adquiere privilegios de LocalSystem, también conocida como "Elevación de Privilegios Fuera de… | |
| Modificada | Alta (7.5) | 50% | 💥 Exploit | Microsoft Internet Explorer | 28/10/2002 | 16/6/2026 | Vulnerabilidad de scripts en marcos cruzados en el control WebBrowser usado en Internet Explorer 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario, leer ficheros arbitrarios, y llevar a cabo otras actividades no autorizadas mediante código que accede a la propiedad Document, lo que evita las… | |
| Modificada | Media (6.8) | 16% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 98Microsoft Windows 98seMicrosoft Windows ME+5 | 4/10/2002 | 16/6/2026 | Las APIs (Application Programming Interface) CertGetCertificateChain CertVerifyCertificateChainPolicy WinVerifyTrust en la CriptoAPI de productos de Microsoft, incluyendo Microsoft Windows 98 a XP, Office para Mac, Internet Explorer para Mac, y Outlook Express para Mac, no verifican adecuadamente las restricciones… | |
| Modificada | Media (5) | 48% | 💥 Exploit | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | La capacidad de isla de datos <script> (legacy - legado - para compatibilidad con anteriores versiones) en XML en Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos leer ficheros XML de su elección, y parte de otros ficheros, mediante una URL cuyo atributo "src" redirige a un fichero local. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | El componente de Carpetas Web en Internet Explorer 5.5 y 6.0 escribe un mensaje de error en una localización conocida en una carpeta temporal, lo que permite a atacantes remotos ejecutar código arbitrario inyectándolo en el mensaje de error, y refiriendose al mensaje de error mediante una URL mhtml: | |
| Modificada | Alta (7.5) | 3.2% | — | ISS Internet Scanner | 24/9/2002 | 16/6/2026 | Buffer overflow in the parsing mechanism for ISS Internet Scanner 6.2.1, when using the license banner HTTP check, allows remote attackers to execute arbitrary code via a long web server response. | |
| Modificada | Media (6.4) | 14% | 💥 Exploit | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet. | |
| Modificada | Alta (7.5) | 13% | — | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to misrepresent the source of a file in the File Download dialogue box to trick users into thinking that the file type is safe to download, aka "File Origin Spoofing." | |
| Modificada | Alta (7.5) | 14% | — | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | Microsoft Internet Explorer 5.01 y 5.5 permite a atacantes remotos ejecutar secuencias de comandos en la zona del PC local mediante una URL que hace referencia un ficherio de recurso local HTML, una variante de la vulnerabilidad "Secuencias de comandos en sitios cruzados en recurso HTML local (Cross-Site Scripting in… | |
| Modificada | Alta (7.5) | 23% | 💥 Exploit | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | Desbordamiento de búfer en el control ActiveX antiguo usado para mostrar texto especialmente formateado en Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario. También conocida como "Desbordamiento de búfer en control ActiveX antiguo de formato de texto" (Buffer Overrun… | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Microsoft Internet Explorer | 24/9/2002 | 16/6/2026 | Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag." | |
| Modificada | Baja (2.6) | 14% | 💥 Exploit | Google ToolbarMicrosoft Internet Explorer | 15/8/2002 | 16/6/2026 | The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect call to the Google.Search() function. | |
| Modificada | Media (5) | 16% | — | Microsoft Internet Explorer | 12/8/2002 | 16/6/2026 | Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size. | |
| Modificada | Media (5) | 37% | 💥 Exploit | Microsoft Internet Information ServerMicrosoft Internet Information Services | 12/8/2002 | 16/6/2026 | Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP… | |
| Modificada | Alta (7.5) | 9.9% | — | Microsoft Internet Explorer | 12/8/2002 | 16/6/2026 | Internet Explorer 5, 5.6, and 6 allows remote attackers to bypass cookie privacy settings and store information across browser sessions via the userData (storeuserData) feature. | |
| Modificada | Alta (7.5) | 3.7% | — | Microsoft Internet ExplorerMozillaNetscape Navigator | 12/8/2002 | 16/6/2026 | The Javascript "Same Origin Policy" (SOP), as implemented in (1) Netscape, (2) Mozilla, and (3) Internet Explorer, allows a remote web server to access HTTP and SOAP/XML content from restricted sites by mapping the malicious server's parent DNS domain name to the restricted site, loading a page from the restricted… | |
| Modificada | Baja (2.6) | 51% | — | Microsoft Internet Information Services | 12/8/2002 | 16/6/2026 | IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method,… | |
| Modificada | Media (5) | 24% | 💥 Exploit | Microsoft Internet Explorer | 12/8/2002 | 16/6/2026 | Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop. | |
| Modificada | Alta (7.5) | 3.3% | — | Symantec Norton Internet SecuritySymantec Norton Personal Firewall | 26/7/2002 | 16/6/2026 | Buffer overflow in HTTP Proxy for Symantec Norton Personal Internet Firewall 3.0.4.91 and Norton Internet Security 2001 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large outgoing HTTP request. | |
| Modificada | Alta (7.5) | 54% | 💥 Exploit | Microsoft Internet ExplorerMicrosoft ISA ServerMicrosoft Proxy ServerUniversity OF Minnesota Gopher | 3/7/2002 | 16/6/2026 | Desbordamiento de búfer en el cliente gopher de Microsoft Internet Explorer 5.1 a la 6.0, Proxy Server 2.0, o ISA Server 2000 permite a atacantes remotos la ejecución de código arbitrario mediante una URL gopher:// que redirige al usuario a un servidor gopher real o simulado que envía una respuesta larga. | |
| Modificada | Alta (7.5) | 31% | — | Microsoft Internet Information ServerMicrosoft Internet Information Services | 3/7/2002 | 16/6/2026 | Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise." | |
| Modificada | Alta (7.5) | 24% | — | Microsoft Internet Explorer | 29/5/2002 | 16/6/2026 | Microsoft Internet Explorer 5.01, 5.5 y 6.0 permite a atacantes remotos ejecutar código arbitrario con menos restricciones de seguridad mediante una página Web malformada que requiere conectividad NetBIOS. También conocida como "Vulnerabilidad de engaño de zona mediante una página Web malformada". | |
| Modificada | Alta (7.5) | 33% | 💥 Exploit | Microsoft Internet Explorer | 29/5/2002 | 16/6/2026 | (repetida de CAN-2002-0193) | |
| Modificada | Alta (7.5) | 11% | — | Microsoft Internet Explorer | 29/5/2002 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en Internet Explorer 6 y anteriores permite que atacante remotos ejecuten código arbitrario por medio de un formulario HTML extendido, cuya salida del servidor remoto no se ha aclarado adecuadamente. |