Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
307 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.5% | — | Realnetworks Helix DNA Server | 28/8/2007 | 16/6/2026 | Heap-based buffer overflow in the RTSP service in Helix DNA Server before 11.1.4 allows remote attackers to execute arbitrary code via an RSTP command containing multiple Require headers. | |
| Modificada | Media (4.3) | 1.8% | — | Wordpress Blix | 22/8/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in the (1) Blix 0.9.1 and (2) Blix 0.9.1 Rus themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF). | |
| Modificada | Media (4.3) | 2.6% | — | Wordpress BlixWordpress BlixedWordpress Blixkrieg | 26/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in a certain index.php installation script related to the (1) Blix 0.9.1, (2) Blixed 1.0, and (3) BlixKrieg (Blix Krieg) 2.2 themes for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter, possibly a related issue to CVE-2007-2757. NOTE:… | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 26/6/2007 | 16/6/2026 | Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2)… | |
| Modificada | Media (5.8) | 1.6% | 💥 Exploit | Galix | 22/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in GaliX 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) galix_cat_detail, (2) galix_gal_detail, and (3) galix_cat_detail_sort parameters. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Realnetworks Helix DNA ServerRealnetworks Helix Mobile ServerRealnetworks Helix Server | 21/11/2006 | 16/6/2026 | Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.0 and 11.1, allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a DESCRIBE request that contains an invalid LoadTestPassword field. | |
| Modificada | Media (5.1) | 3.0% | 💥 Exploit | Basilix Webmail | 5/10/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f)… | |
| Modificada | Alta (7.5) | 14% | — | Realnetworks Helix DNA Server | 28/6/2006 | 16/6/2026 | Heap-based buffer overflow in RealNetworks Helix DNA Server 10.0 and 11.0 allows remote attackers to execute arbitrary code via (1) a long User-Agent HTTP header in the RTSP service and (2) unspecified vectors involving the "parsing of HTTP URL schemes". | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 23/3/2006 | 16/6/2026 | Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified… | |
| Modificada | Alta (9.3) | 5.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which… | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability… | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realplayer | 27/9/2005 | 16/6/2026 | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file. | |
| Modificada | Media (5.1) | 3.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files. | |
| Modificada | Media (5.1) | 3.4% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 19/4/2005 | 16/6/2026 | Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file. | |
| Modificada | Media (5.1) | 4.3% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 31/12/2004 | 16/6/2026 | Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 1.9% | — | Realnetworks Helix Universal Mobile Server AND GatewayRealnetworks Helix Universal Server | 3/11/2004 | 16/6/2026 | RealNetworks Helix Universal Server 9.0.2 for Linux and 9.0.3 for Windows allows remote attackers to cause a denial of service (CPU and memory exhaustion) via a POST request with a Content-Length header set to -1. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Realnetworks Helix Universal Server | 1/6/2004 | 16/6/2026 | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests. | |
| Modificada | Media (6.8) | 1.5% | — | Realnetworks Helix Universal Mobile ServerRealnetworks Helix Universal Server | 17/2/2004 | 16/6/2026 | Helix Universal Server/Proxy 9 and Mobile Server 10 allow remote attackers to cause a denial of service via certain HTTP POST messages to the Administration System port. | |
| Modificada | Alta (7.5) | 49% | 💥 Exploit | Realnetworks Helix Universal ServerRealnetworks Realserver | 20/10/2003 | 16/6/2026 | Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code. | |
| Modificada | Baja (3.6) | 0.33% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | The attachment capability in Compose Mail in BasiliX Webmail 1.1.0 does not check whether the attachment was uploaded by the user or came from a HTTP POST, which could allow local users to steal sensitive information like a password file. | |
| Modificada | Media (6.4) | 1.2% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in BasiliX Webmail 1.10 allows remote attackers to obtain sensitive information or possibly modify data via the id variable. | |
| Modificada | Baja (2.1) | 0.35% | — | Basilix Webmail | 31/12/2002 | 16/6/2026 | BasiliX 1.1.0 saves attachments in a world readable /tmp/BasiliX directory, which allows local users to read other users' attachments. | |
| Modificada | Media (6.8) | 4.3% | 💥 Exploit | Basilix Webmail | 31/12/2002 | 16/6/2026 | Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as other users by injecting script into the (1) subject or (2) message fields. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Realnetworks Helix Universal Server | 19/12/2002 | 16/6/2026 | Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments. | |
| Modificada | Alta (7.5) | 1.8% | — | Oblix Netpoint | 12/8/2002 | 16/6/2026 | The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again. |