Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 6.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record. | |
| Modificada | Media (6.5) | 3.0% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 7.5% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file. | |
| Modificada | Alta (8.8) | 11% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file. | |
| Modificada | Alta (8.8) | 7.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file. | |
| Modificada | Alta (8.8) | 6.3% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error. | |
| Modificada | Alta (9.3) | 5.0% | — | Adobe DirectorAdobe Shockwave Player | 13/5/2010 | 16/6/2026 | Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation. | |
| Modificada | Alta (8.8) | 5.1% | — | Adobe Shockwave Player | 13/5/2010 | 16/6/2026 | Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file. | |
| Modificada | Alta (9.3) | 7.4% | — | Adobe Shockwave Player | 21/1/2010 | 16/6/2026 | Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a… | |
| Modificada | Alta (9.3) | 8.7% | — | Adobe Shockwave Player | 21/1/2010 | 16/6/2026 | Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file. | |
| Modificada | Alta (9.3) | 4.4% | 💥 Exploit | Autodesk Alias Wavefront MayaAutodesk Maya | 24/11/2009 | 16/6/2026 | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes." | |
| Modificada | Alta (9.3) | 4.2% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.1% | — | Adobe Shockwave Player | 4/11/2009 | 16/6/2026 | Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 20% | 💥 Exploit | Adobe Shockwave Player | 18/9/2009 | 16/6/2026 | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value. | |
| Modificada | Alta (9.3) | 4.7% | — | Adobe Shockwave Player | 25/6/2009 | 16/6/2026 | Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465." | |
| Modificada | Alta (9.3) | 5.6% | — | Adobe Shockwave Player | 25/6/2009 | 16/6/2026 | Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content. | |
| Modificada | Media (4.3) | 3.0% | — | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method. | |
| Modificada | Media (5) | 14% | 💥 Exploit | Trustwave ModsecurityFedoraproject Fedora | 3/6/2009 | 16/6/2026 | The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Wavelink Media Tutorialcms | 15/1/2008 | 16/6/2026 | SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter. | |
| Modificada | Alta (10) | 32% | 💥 Exploit | Adobe Shockwave Player | 14/11/2007 | 16/6/2026 | Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long argument to the ShockwaveVersion method. | |
| Modificada | Media (5) | 6.2% | — | Adobe Shockwave Player | 8/10/2007 | 16/6/2026 | The Adobe Macromedia Flash 9 plug-in allows remote attackers to cause a victim machine to establish TCP sessions with arbitrary hosts via a Flash (SWF) movie, related to lack of pinning of a hostname to a single IP address after receiving an allow-access-from element in a cross-domain-policy XML document, and the… |