Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
57 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.40% | — | Autodesk Advanced Material ExchangeAutodesk Moldflow AdviserAutodesk Moldflow CommunicatorAutodesk Moldflow Synergy | 3/10/2022 | 17/6/2026 | A malicious crafted file consumed through Moldflow Synergy, Moldflow Adviser, Moldflow Communicator, and Advanced Material Exchange applications could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | |
| Modificada | Alta (7.5) | 1.3% | — | Cisco Unified Personal Communicator | 16/1/2020 | 16/6/2026 | Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition. | |
| Modificada | Alta (7.8) | 0.34% | — | GE Communicator | 9/5/2019 | 17/6/2026 | GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to replace the uninstaller with a malicious version, which could allow an attacker to gain administrator privileges to the system. | |
| Modificada | Alta (7.8) | 0.42% | — | GE Communicator | 9/5/2019 | 17/6/2026 | GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade. | |
| Modificada | Crítica (9.8) | 1.3% | — | GE Communicator | 9/5/2019 | 17/6/2026 | GE Communicator, all versions prior to 4.0.517, contains two backdoor accounts with hardcoded credentials, which may allow control over the database. This service is inaccessible to attackers if Windows default firewall settings are used by the end user. | |
| Modificada | Alta (7.8) | 0.83% | — | GE Communicator | 9/5/2019 | 17/6/2026 | GE Communicator, all versions prior to 4.0.517, allows an attacker to place malicious files within the working directory of the program, which may allow an attacker to manipulate widgets and UI elements. | |
| Modificada | Media (5.6) | 1.2% | — | GE Communicator | 9/5/2019 | 17/6/2026 | GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is inaccessible to attackers if Windows… | |
| Modificada | Media (5.5) | 0.28% | — | Avaya One-x Communicator | 27/2/2019 | 17/6/2026 | Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensitive information. Affected versions include all 6.2.x versions prior to 6.2 SP13. | |
| Modificada | Alta (7.6) | 0.99% | — | Gigasoft ProessentialsGE Communicator | 2/10/2018 | 17/6/2026 | A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 and prior. A malicious HTML file that loads the ActiveX controls can trigger the vulnerability via unchecked function calls. | |
| Modificada | Media (5) | 2.4% | — | Cisco IP Communicator | 8/7/2015 | 17/6/2026 | Cisco IP Communicator 8.6(4) allows remote attackers to cause a denial of service (service outage) via an unspecified URL in a GET request, aka Bug ID CSCuu37656. | |
| Modificada | Alta (9.3) | 22% | — | Microsoft LyncMicrosoft Lync ServerMicrosoft Office Communicator | 15/5/2013 | 16/6/2026 | Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vulnerability." | |
| Modificada | Media (4.3) | 28% | — | Microsoft Groove ServerMicrosoft InfopathMicrosoft LyncMicrosoft Office Communicator+4 | 9/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1… | |
| Modificada | Media (5) | 0.52% | — | Cisco IP Communicator | 6/8/2012 | 16/6/2026 | Cisco IP Communicator 8.6 allows man-in-the-middle attackers to modify the Certificate Trust List via unspecified vectors, aka Bug ID CSCtz01471. | |
| Modificada | Media (4.3) | 22% | — | Microsoft LyncMicrosoft Office CommunicatorMicrosoft Internet Explorer | 12/6/2012 | 16/6/2026 | The toStaticHTML API (aka the SafeHTML component) in Microsoft Internet Explorer 8 and 9, Communicator 2007 R2, and Lync 2010 and 2010 Attendee does not properly handle event attributes and script, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted HTML document, aka… | |
| Modificada | Media (5) | 1.2% | — | Cisco IP Communicator | 2/5/2012 | 16/6/2026 | The sccp-protocol component in Cisco IP Communicator (CIPC) 7.0 through 8.6 does not limit the rate of SCCP messages to Cisco Unified Communications Manager (CUCM), which allows remote attackers to cause a denial of service via vectors that trigger (1) on hook and (2) off hook messages, as demonstrated by a… | |
| Modificada | Alta (10) | 65% | — | Njstar Communicator | 21/11/2011 | 16/6/2026 | Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Alta (9.3) | 2.3% | — | Garmin Communicator Plugin | 11/5/2009 | 16/6/2026 | The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4.0 does not properly enforce the restrictions that (1) download and (2) upload requests come from a web site specified by the user, which allows remote attackers to… | |
| Modificada | Media (5) | 13% | — | Microsoft Office Communicator | 20/11/2008 | 16/6/2026 | Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numbers of emoticons. | |
| Modificada | Media (5.3) | 68% | — | Microsoft Office Communicator | 20/11/2008 | 16/6/2026 | Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions. | |
| Modificada | Media (5) | 16% | — | Microsoft Office Communications ServerMicrosoft Office CommunicatorMicrosoft Windows Live Messenger | 20/11/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Office Communications Server (OCS), Office Communicator, and Windows Live Messenger allows remote attackers to cause a denial of service (crash) via a crafted Real-time Transport Control Protocol (RTCP) receiver report packet. | |
| Modificada | Alta (7.5) | 17% | — | Microsoft AccessMicrosoft ExcelMicrosoft FrontpageMicrosoft Groove+13 | 7/7/2008 | 16/6/2026 | Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times… | |
| Modificada | Baja (3.5) | 1.2% | — | Cisco ACS Solution EngineCiscoworksCisco IP CommunicatorCisco Meetingplace+14 | 16/3/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) PreSearch.html and (2) PreSearch.class in Cisco Secure Access Control Server (ACS), VPN Client, Unified Personal Communicator, MeetingPlace, Unified MeetingPlace, Unified MeetingPlace Express, CallManager, IP Communicator, Unified Video Advantage, Unified… | |
| Modificada | Media (6.4) | 2.0% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 4.0 through 4.79 allows remote attackers to bypass JVM security and execute arbitrary Java code via an applet that loads user-supplied Java classes. | |
| Modificada | Media (5) | 1.1% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Netscape Communicator 6.2.1 allows remote attackers to cause a denial of service in client browsers via a webpage containing a recursive META refresh tag where the content tag is blank and the URL tag references itself. | |
| Modificada | Alta (10) | 5.8% | — | Netscape Communicator | 31/12/2002 | 16/6/2026 | Buffer overflow in the sun.awt.windows.WDefaultFontCharset Java class implementation in Netscape 4.0 allows remote attackers to execute arbitrary code via an applet that calls the WDefaultFontCharset constructor with a long string and invokes the canConvert method. |