Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | — | Videolan VLC Media PlayerOpensuse | 31/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned… | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a… | |
| Modificada | Alta (7.8) | 2.4% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value. | |
| Modificada | Alta (7.8) | 2.2% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7. | |
| Modificada | Alta (7.8) | 1.1% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7. | |
| Modificada | Alta (7.8) | 2.4% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an… | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | Daum Potplayer | 14/1/2020 | 17/6/2026 | PotPlayer 1.5.40688: .avi File Memory Corruption | |
| Modificada | Media (5.5) | 0.87% | — | Smplayer | 2/12/2019 | 17/6/2026 | SMPlayer 19.5.0 has a buffer overflow via a long .m3u file. | |
| Modificada | Alta (7.8) | 0.42% | — | Videolan VLC Media Player | 23/10/2019 | 17/6/2026 | When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue. | |
| Modificada | Alta (7.8) | 0.45% | — | Kmplayer | 8/10/2019 | 17/6/2026 | KMPlayer 4.2.2.31 allows a User Mode Write AV starting at utils!src_new+0x000000000014d6ee. | |
| Modificada | Alta (7.5) | 2.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerGoogle ChromeDebian Linux+1 | 27/9/2019 | 17/6/2026 | Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user. | |
| Modificada | Crítica (9.8) | 5.9% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 12/9/2019 | 17/6/2026 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Use after free vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. | |
| Modificada | Crítica (9.8) | 4.3% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 12/9/2019 | 17/6/2026 | Adobe Flash Player 32.0.0.238 and earlier versions, 32.0.0.207 and earlier versions have a Same Origin Method Execution vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. | |
| Modificada | Alta (7.8) | 1.9% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file. | |
| Modificada | Media (5.5) | 1.4% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file. | |
| Modificada | Alta (7.8) | 1.8% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 29/8/2019 | 17/6/2026 | The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file. | |
| Modificada | Media (5.3) | 1.5% | — | Foliovision FV Flowplayer Video Player | 15/8/2019 | 17/6/2026 | The FV Flowplayer Video Player plugin before 7.3.15.727 for WordPress allows guests to obtain the email subscription list in CSV format via the wp-admin/admin-post.php?page=fvplayer&fv-email-export=1 URI. |