Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.96% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted mp4 file. | |
| Modificada | Media (5.5) | 0.89% | — | Audiocoding Freeware Advanced Audio Decoder 2 | 27/6/2017 | 17/6/2026 | The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file. | |
| Modificada | Media (4) | 1.3% | — | Rhodecode Enterprise | 16/2/2015 | 17/6/2026 | RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method. | |
| Modificada | Media (4) | 1.8% | — | Kallithea-scm KallitheaRhodecode Enterprise | 16/2/2015 | 17/6/2026 | RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method. | |
| Modificada | Media (6.9) | 0.41% | — | Vmware Movie Decoder | 5/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory. | |
| Modificada | Alta (9.3) | 5.8% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 6/12/2010 | 16/6/2026 | The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build… | |
| Modificada | Media (6.9) | 0.28% | — | Ponsoftware Archive Decoder | 25/10/2010 | 16/6/2026 | Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory. | |
| Modificada | Alta (9.3) | 6.2% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 12/4/2010 | 16/6/2026 | vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file… | |
| Modificada | Alta (9.3) | 6.2% | — | Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server | 12/4/2010 | 16/6/2026 | Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute… | |
| Modificada | Alta (9.3) | 5.6% | — | Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation | 8/9/2009 | 16/6/2026 | The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might… | |
| Modificada | Alta (9.3) | 5.0% | — | Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation | 8/9/2009 | 16/6/2026 | Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute… | |
| Modificada | Alta (9.3) | 5.7% | — | Foxitsoftware Jpeg2000 Jbig2 Decoder Add-onFoxitsoftware Foxit Reader | 23/6/2009 | 16/6/2026 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary… | |
| Modificada | Alta (9.3) | 5.7% | — | Foxitsoftware Foxit ReaderFoxitsoftware Jpeg2000/jbig2 Decoder Add-on | 23/6/2009 | 16/6/2026 | The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute… | |
| Modificada | Alta (9) | 7.1% | — | MW6 Technologies 1D Barcode Decoder Activex | 4/11/2008 | 16/6/2026 | Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods. | |
| Modificada | Alta (10) | 13% | — | Digital Data Communications Rtspvapgdecoder.dll | 22/1/2008 | 16/6/2026 | Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property. | |
| Modificada | Alta (10) | 3.0% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote… | |
| Modificada | Alta (9) | 2.1% | — | Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP | 6/9/2007 | 16/6/2026 | The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows… | |
| Modificada | Alta (10) | 6.0% | — | Nobreak Technologies CrazywwwboardQdecoder | 3/5/2001 | 16/6/2026 | Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header. |