Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 3.2% | 💥 Exploit | Kmplayer | 28/11/2017 | 17/6/2026 | KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file. | |
| Modificada | Alta (9.3) | 24% | 💥 Exploit | Mplayer2Ricardo Villalba Smplayer | 11/6/2014 | 16/6/2026 | Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a SAMI subtitle file. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | Castillobueno Ccmplayer | 15/9/2012 | 16/6/2026 | Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist. | |
| Modificada | Alta (9.3) | 3.3% | — | Kmplayer | 3/7/2012 | 16/6/2026 | Untrusted search path vulnerability in KMPlayer 3.2.0.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ehtrace.dll that is located in the current working directory. | |
| Modificada | Alta (9.3) | 4.0% | — | Kmplayer | 2/9/2011 | 16/6/2026 | Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field. | |
| Modificada | Alta (10) | 2.3% | — | FfmpegMplayerhq MplayerMandriva Corporate ServerMandriva Enterprise Server+1 | 20/5/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by… | |
| Modificada | Alta (9.3) | 1.7% | — | FfmpegMplayerhq Mplayer | 20/5/2011 | 16/6/2026 | The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723. | |
| Modificada | Media (6.8) | 4.4% | — | FfmpegMplayer | 20/5/2011 | 16/6/2026 | FFmpeg 0.5.x, as used in MPlayer and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed VC-1 file. | |
| Modificada | Media (6.8) | 4.2% | — | FfmpegMplayerhq Mplayer | 20/5/2011 | 16/6/2026 | FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file. | |
| Modificada | Media (6.8) | 3.0% | — | FfmpegMplayerhq Mplayer | 20/5/2011 | 16/6/2026 | FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed WMV file. | |
| Modificada | Media (6.8) | 4.2% | — | Ffmpeg LibavcodecFfmpegMplayerhq Mplayer | 30/9/2010 | 16/6/2026 | flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability." | |
| Modificada | Alta (9.3) | 5.6% | 💥 Exploit | KDE Kmplayer | 20/8/2009 | 16/6/2026 | Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 31% | 💥 Exploit | TFM Mmplayer | 21/7/2009 | 16/6/2026 | Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file. | |
| Modificada | Alta (10) | 7.7% | — | Mplayer | 17/12/2008 | 16/6/2026 | Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file. | |
| Modificada | Media (5) | 9.3% | 💥 Exploit | Mplayer | 20/10/2008 | 16/6/2026 | MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718. | |
| Modificada | Media (4.3) | 1.5% | — | Mplayer | 20/10/2008 | 16/6/2026 | MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a… | |
| Modificada | Alta (9.3) | 11% | — | Mplayer | 29/9/2008 | 16/6/2026 | Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibly execute arbitrary code via a crafted video file that causes the stream_read function to read or write arbitrary memory. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Mplayer | 31/3/2008 | 16/6/2026 | Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow. | |
| Modificada | Media (6.8) | 3.9% | — | Mplayer | 6/2/2008 | 16/6/2026 | Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code. | |
| Modificada | Media (4.3) | 2.8% | — | Mplayer | 6/2/2008 | 16/6/2026 | Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title. | |
| Modificada | Alta (7.5) | 5.4% | — | MplayerXine-lib | 5/2/2008 | 16/6/2026 | Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow. | |
| Modificada | Alta (9.3) | 8.9% | 💥 Exploit | Mplayer | 5/2/2008 | 16/6/2026 | Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag. | |
| Modificada | Alta (9.3) | 4.4% | — | Guliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer | 18/9/2007 | 16/6/2026 | Multiple integer overflows in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi file with certain… | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Guliverkli Media Player ClassicMympc Cd-stormVerycd Stormplayer | 18/9/2007 | 16/6/2026 | Heap-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9.0 and earlier, as used standalone and in mympc (aka CD-Storm) 1.0.0.1, StormPlayer 1.0.4, and possibly other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a .avi… | |
| Modificada | Alta (7.1) | 3.1% | 💥 Exploit | KDE Kmplayer | 18/9/2007 | 16/6/2026 | KMPlayer 2.9.3.1210 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a .avi file with certain large "indx truck size" and nEntriesInuse values. |