Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.96%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted mp4 file.
ModificadaMedia (5.5)0.89%—Audiocoding Freeware Advanced Audio Decoder 227/6/201717/6/2026
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
ModificadaMedia (4)1.3%—Rhodecode Enterprise16/2/201517/6/2026
RhodeCode before 2.2.7 allows remote authenticated users to obtain API keys and other sensitive information via the (1) update_repo, (2) get_locks, or (3) get_user_groups API method.
ModificadaMedia (4)1.8%—Kallithea-scm KallitheaRhodecode Enterprise16/2/201517/6/2026
RhodeCode before 2.2.7 and Kallithea 0.1 allows remote authenticated users to obtain API keys and other sensitive information via the get_repo API method.
ModificadaMedia (6.9)0.41%—Vmware Movie Decoder5/10/201216/6/2026
Untrusted search path vulnerability in the installer in VMware Movie Decoder before 9.0 allows local users to gain privileges via a Trojan horse executable file in the installer directory.
ModificadaAlta (9.3)5.8%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server6/12/201016/6/2026
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build…
ModificadaMedia (6.9)0.28%—Ponsoftware Archive Decoder25/10/201016/6/2026
Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.
ModificadaAlta (9.3)6.2%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server12/4/201016/6/2026
vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file…
ModificadaAlta (9.3)6.2%—Vmware Movie DecoderVmware WorkstationVmware PlayerVmware Server12/4/201016/6/2026
Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute…
ModificadaAlta (9.3)5.6%—Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation8/9/200916/6/2026
The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might…
ModificadaAlta (9.3)5.0%—Vmware ACEVmware Movie DecoderVmware PlayerVmware Workstation8/9/200916/6/2026
Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute…
ModificadaAlta (9.3)5.7%—Foxitsoftware Jpeg2000 Jbig2 Decoder Add-onFoxitsoftware Foxit Reader23/6/200916/6/2026
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during decoding of a JPEG2000 (aka JPX) header, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary…
ModificadaAlta (9.3)5.7%—Foxitsoftware Foxit ReaderFoxitsoftware Jpeg2000/jbig2 Decoder Add-on23/6/200916/6/2026
The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute…
ModificadaAlta (9)7.1%—MW6 Technologies 1D Barcode Decoder Activex4/11/200816/6/2026
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.
ModificadaAlta (10)13%—Digital Data Communications Rtspvapgdecoder.dll22/1/200816/6/2026
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows remote attackers to execute arbitrary code via a long MP4Prefix property.
ModificadaAlta (10)3.0%—Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP6/9/200716/6/2026
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier does not require authentication, which allows remote…
ModificadaAlta (9)2.1%—Cisco Video Surveillance IP Gateway Encoder DecoderCisco Video Surveillance SP ISP Decoder SoftwareCisco Video Surveillance SP ISP6/9/200716/6/2026
The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Software firmware 1.11.0 and earlier, and the Video Surveillance SP/ISP firmware 1.23.7 and earlier have default passwords for the sypixx and root user accounts, which allows…
ModificadaAlta (10)6.0%—Nobreak Technologies CrazywwwboardQdecoder3/5/200116/6/2026
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.