Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

223 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.74%—Videolan VLC Media Player26/7/202117/6/2026
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
ModificadaAlta (7.1)1.5%💥 PoCVideolan VLC Media Player26/7/202117/6/2026
A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux8/1/20219/7/2026
A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
ModificadaAlta (7.8)2.4%—Videolan VLC Media PlayerDebian Linux8/6/202017/6/2026
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file.
ModificadaAlta (7.8)2.0%—Videolan VLC Media Player15/5/202017/6/2026
An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product.
ModificadaAlta (7.8)2.2%—Abbs Software Audio Media Player Project Abbs Software Audio Media Player29/4/202017/6/2026
ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow.
ModificadaMedia (5.3)1.1%—Videolan VLC Media Player6/2/202016/6/2026
The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating.
ModificadaMedia (6.1)1.6%—Videolan VLC Media PlayerOpensuse31/1/202016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned…
ModificadaAlta (7.8)1.5%—Videolan VLC Media Player24/1/202017/6/2026
The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a…
ModificadaAlta (7.8)2.4%—Videolan VLC Media Player24/1/202017/6/2026
Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value.
ModificadaAlta (7.8)2.2%—Videolan VLC Media Player24/1/202017/6/2026
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7.
ModificadaAlta (7.8)1.1%—Videolan VLC Media Player24/1/202017/6/2026
The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large box size.
ModificadaAlta (7.8)1.5%—Videolan VLC Media Player24/1/202017/6/2026
Integer underflow in the MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a box size less than 7.
ModificadaAlta (7.8)2.4%—Videolan VLC Media Player24/1/202017/6/2026
The GetUpdateFile function in misc/update.c in the Updater in VideoLAN VLC media player before 2.1.6 performs an incorrect cast operation from a 64-bit integer to a 32-bit integer, which allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted update status file, aka an…
ModificadaAlta (7.8)0.42%—Videolan VLC Media Player23/10/201917/6/2026
When executing VideoLAN VLC media player 3.0.8 with libqt on Windows, Data from a Faulting Address controls Code Flow starting at libqt_plugin!vlc_entry_license__3_0_0f+0x00000000003b9aba. NOTE: the VideoLAN security team indicates that they have not been contacted, and have no way of reproducing this issue.
ModificadaAlta (7.8)1.9%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.
ModificadaMedia (5.5)1.4%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.
ModificadaAlta (7.8)1.8%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.
ModificadaAlta (7.8)1.5%—Videolan VLC Media PlayerDebian Linux29/8/201917/6/2026
The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.
Orbitaley — Vulnerabilidades