Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a crafted RAW file, as demonstrated using a KDC file with a certain size. | |
| Modificada | Alta (7.5) | 1.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated using a KDC file with a DSLR-A100 model and certain sequences of tags. | |
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF StripByteCounts tag. | |
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPEG tag value and a small size. | |
| Modificada | Alta (9.3) | 4.3% | — | Google Picasa | 28/7/2011 | 16/6/2026 | Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file. | |
| Modificada | Media (6.9) | 0.32% | — | Google Picasa | 28/3/2011 | 16/6/2026 | Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory. | |
| Modificada | Media (6.8) | 9.4% | 💥 Exploit | Masselink COM Picasa2gallery | 28/6/2010 | 16/6/2026 | Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Roberto Aloi COM Joomlapicasa2 | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 1.7% | — | Americasarmy America's Army | 6/8/2008 | 16/6/2026 | America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet, probably involving a VoiceIndex value that is outside of the range specified by VOICE_MAX_CHATTERS. | |
| Modificada | Media (4.3) | 1.5% | — | Americasarmy America's ArmyAmericasarmy America's Army Special Forces | 6/10/2007 | 16/6/2026 | The Windows dedicated server for the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allows remote attackers to cause a denial of service (server hang) via packets containing 0x07 characters or other unspecified invalid characters. NOTE:… | |
| Modificada | Media (4.3) | 1.6% | — | Americasarmy America's ArmyAmericasarmy America's Army Special Forces | 6/10/2007 | 16/6/2026 | Multiple buffer overflows in the logging function in the Unreal engine, as used by America's Army and America's Army Special Forces 2.8.2 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to cause a denial of service (daemon crash) via a long (1) PB_Y packet to the YPG server on UDP port 1716 or (2)… | |
| Modificada | Media (5) | 0.53% | — | Google Picasa | 12/9/2007 | 16/6/2026 | Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory. | |
| Modificada | Media (6.8) | 0.44% | — | Google Picasa | 11/9/2007 | 16/6/2026 | Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory. | |
| Modificada | Alta (7.5) | 0.47% | — | Google Picasa | 11/9/2007 | 16/6/2026 | Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory. | |
| Modificada | Media (5) | 2.6% | — | Activision Call OF DutyActivision Call OF Duty United OffensiveActivision Return TO Castle WolfensteinID Software Quake 3 Arena+6 | 2/5/2005 | 16/6/2026 | Quake 3 engine, as used in multiple games, allows remote attackers to cause a denial of service (client disconnect) via a long message, which is not properly truncated and causes the engine to process the remaining data as if it were network data. | |
| Modificada | Media (5) | 4.3% | 💥 Exploit | Lucasarts Star Wars Jedi Knight Jedi Academy | 2/5/2005 | 16/6/2026 | Buffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute arbitrary code via a long message using commands such as (1) say and (2) tell. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a join request that contains a memory address that causes the server to read arbitrary memory. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Lucasarts Star Wars Battlefront | 10/1/2005 | 16/6/2026 | Buffer overflow in Star Wars Battlefront 1.11 and earlier allows remote attackers to cause a denial of service (application crash) via a long nickname. |