Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
–

57 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.40%—Autodesk Advanced Material ExchangeAutodesk Moldflow AdviserAutodesk Moldflow CommunicatorAutodesk Moldflow Synergy3/10/202217/6/2026
A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.5)1.3%—Cisco Unified Personal Communicator16/1/202016/6/2026
Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition.
ModificadaAlta (7.8)0.34%—GE Communicator9/5/201917/6/2026
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system.
ModificadaAlta (7.8)0.42%—GE Communicator9/5/201917/6/2026
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.
ModificadaCrítica (9.8)1.3%—GE Communicator9/5/201917/6/2026
GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user.
ModificadaAlta (7.8)0.83%—GE Communicator9/5/201917/6/2026
GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements.
ModificadaMedia (5.6)1.2%—GE Communicator9/5/201917/6/2026
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows…
ModificadaMedia (5.5)0.28%—Avaya One-x Communicator27/2/201917/6/2026
Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13.
ModificadaAlta (7.6)0.99%—Gigasoft ProessentialsGE Communicator2/10/201817/6/2026
A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls.
ModificadaMedia (5)2.4%—Cisco IP Communicator8/7/201517/6/2026
Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified URL in a GET request, aka Bug ID CSCuu37656.
ModificadaAlta (9.3)22%—Microsoft LyncMicrosoft Lync ServerMicrosoft Office Communicator15/5/201316/6/2026
Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability."
ModificadaMedia (4.3)28%—Microsoft Groove ServerMicrosoft InfopathMicrosoft LyncMicrosoft Office Communicator+49/10/201216/6/2026
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1…
ModificadaMedia (5)0.52%—Cisco IP Communicator6/8/201216/6/2026
Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471.
ModificadaMedia (4.3)22%—Microsoft LyncMicrosoft Office CommunicatorMicrosoft Internet Explorer12/6/201216/6/2026
The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka…
ModificadaMedia (5)1.2%—Cisco IP Communicator2/5/201216/6/2026
The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a…
ModificadaAlta (10)65%—Njstar Communicator21/11/201116/6/2026
Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet.
ModificadaAlta (9.3)2.3%—Garmin Communicator Plugin11/5/200916/6/2026
The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4.0 does not properly enforce the restrictions that (1) download and (2) upload requests come from a web site specified by the user, which allows remote attackers to…
ModificadaMedia (5)13%—Microsoft Office Communicator20/11/200816/6/2026
Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numbers of emoticons.
ModificadaMedia (5.3)68%—Microsoft Office Communicator20/11/200816/6/2026
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.
ModificadaMedia (5)16%—Microsoft Office Communications ServerMicrosoft Office CommunicatorMicrosoft Windows Live Messenger20/11/200816/6/2026
Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet.
ModificadaAlta (7.5)17%—Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+137/7/200816/6/2026
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times…
ModificadaBaja (3.5)1.2%—Cisco ACS Solution EngineCiscoworksCisco IP CommunicatorCisco Meetingplace+1416/3/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified…
ModificadaMedia (6.4)2.0%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes.
ModificadaMedia (5)1.1%—Netscape Communicator31/12/200216/6/2026
Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself.
ModificadaAlta (10)5.8%—Netscape Communicator31/12/200216/6/2026
Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method.