Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 8.8% | 💥 Exploit | Microsoft Windows Media Player | 26/2/2010 | 16/6/2026 | Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file. | |
| Modificada | Alta (9.3) | 24% | — | Microsoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP | 13/12/2009 | 16/6/2026 | Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file. | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows Media Player | 14/10/2009 | 16/6/2026 | Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka "WMP Heap Overflow Vulnerability." | |
| Modificada | Alta (9.3) | 23% | — | Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2)… | |
| Modificada | Alta (9.3) | 27% | — | Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+3 | 14/10/2009 | 16/6/2026 | Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media… | |
| Modificada | Alta (8.5) | 16% | — | Microsoft Windows Media Format RuntimeMicrosoft Windows 2000Microsoft Windows XPMicrosoft Windows Server 2003+4 | 8/9/2009 | 16/6/2026 | Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows Media Format RuntimeMicrosoft Windows 2000Microsoft Windows XPMicrosoft Windows Server 2003+4 | 8/9/2009 | 16/6/2026 | Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing… | |
| Modificada | Alta (9.3) | 18% | 💥 Exploit | Microsoft Windows Media Player | 17/4/2009 | 16/6/2026 | Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid. | |
| Modificada | Media (4.3) | 21% | 💥 Exploit | Microsoft Windows Media Player | 29/12/2008 | 16/6/2026 | Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a… | |
| Modificada | Alta (10) | 15% | — | Microsoft Windows Media Player | 10/12/2008 | 16/6/2026 | Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1 and 9 incorrectly associate ISATAP addresses with the Local Intranet zone, which allows remote servers to capture NTLM credentials, and execute arbitrary code through credential-reflection attacks, by… | |
| Modificada | Alta (10) | 16% | — | Microsoft Windows Media PlayerMicrosoft Windows Media Format RuntimeMicrosoft Windows Media Services | 10/12/2008 | 16/6/2026 | Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ… | |
| Modificada | Media (4.3) | 4.0% | — | Microsoft Windows Media Player | 4/11/2008 | 16/6/2026 | Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Alta (9.3) | 55% | 💥 Exploit | Microsoft Windows Media EncoderMicrosoft Windows-ntMicrosoft Windows 2000Microsoft Windows 2003 Server+1 | 11/9/2008 | 16/6/2026 | Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability." | |
| Modificada | Alta (9.3) | 30% | — | Microsoft Windows Media Player | 11/9/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling Rate Vulnerability." | |
| Modificada | Alta (10) | 34% | — | Microsoft Windows Messenger | 13/8/2008 | 16/6/2026 | An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video connections without notification via unknown vectors. | |
| Modificada | Alta (9.3) | 30% | 💥 Exploit | 3ivx Mpeg-4 CodecMicrosoft Windows Media Player | 17/12/2007 | 16/6/2026 | Stack-based buffer overflow in mplayer2.exe in Microsoft Windows Media Player (WMP) 6.4, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6402. | |
| Modificada | Alta (9.3) | 36% | — | Microsoft Windows Media Format RuntimeMicrosoft Windows Media Services | 12/12/2007 | 16/6/2026 | Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file. | |
| Modificada | Media (5) | 19% | 💥 Exploit | Microsoft Windows Media Player | 4/12/2007 | 16/6/2026 | Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a divide-by-zero error, as demonstrated by kr.aiff. | |
| Modificada | Alta (7.5) | 15% | — | Microsoft Windows Media Player | 26/9/2007 | 16/6/2026 | Microsoft Windows Media Player (WMP) 9 on Windows XP SP2 invokes Internet Explorer to render HTML documents contained inside some media files, regardless of what default web browser is configured, which might allow remote attackers to exploit vulnerabilities in software that the user does not expect to run, as… | |
| Modificada | Media (4) | 22% | — | Microsoft Windows Media Player | 14/8/2007 | 16/6/2026 | Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that causes a size mismatch between compressed and decompressed data and triggers a heap-based buffer overflow, aka "Windows Media Player Code Execution… | |
| Modificada | Alta (7.6) | 25% | — | Microsoft Windows Media Player | 14/8/2007 | 16/6/2026 | Unspecified vulnerability in Microsoft Windows Media Player 7.1, 9, 10, and 11 allows remote attackers to execute arbitrary code via a skin file (WMZ or WMD) with crafted header information that is not properly handled during decompression, aka "Windows Media Player Code Execution Vulnerability Decompressing Skins." | |
| Modificada | Media (4.3) | 15% | 💥 Exploit | Microsoft Windows Media Player | 9/8/2007 | 16/6/2026 | Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted .au file that triggers a divide-by-zero error, as demonstrated by iapetus.au. | |
| Modificada | Alta (10) | 6.2% | 💥 Exploit | Telestream Flip4mac Windows Media Components FOR Quicktime | 31/1/2007 | 16/6/2026 | Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code via a crafted ASF_File_Properties_Object size field in a WMV file, which triggers memory corruption. | |
| Modificada | Media (6.8) | 28% | — | Microsoft Windows Media PlayerMicrosoft Windows 2003 ServerMicrosoft Windows XP | 13/12/2006 | 16/6/2026 | Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file. | |
| Modificada | Alta (7.5) | 42% | — | Microsoft Windows Media Player | 28/11/2006 | 16/6/2026 | Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an… |