Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 9.8% | 💥 Exploit | Lame Project Lame | 25/6/2017 | 17/6/2026 | The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file. | |
| Modificada | Alta (7.8) | 1.5% | — | Lame Project Lame | 25/6/2017 | 17/6/2026 | The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file. | |
| Modificada | Media (5.5) | 1.2% | — | Lame Project Lame | 25/6/2017 | 17/6/2026 | The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type == 2" case, a similar issue to… | |
| Modificada | Media (5.5) | 4.1% | 💥 Exploit | Lame Project Lame | 25/6/2017 | 17/6/2026 | The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. | |
| Modificada | Media (5.5) | 1.8% | — | Lame Project Lame | 25/6/2017 | 17/6/2026 | The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. | |
| Modificada | Media (5.5) | 1.4% | — | Lame Project Lame | 25/6/2017 | 17/6/2026 | The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file. | |
| Modificada | Media (5.5) | 1.4% | — | Lame Project Lame | 25/6/2017 | 17/6/2026 | The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate. | |
| Modificada | Alta (7.8) | 1.5% | — | Lame Project Lame | 2/5/2017 | 17/6/2026 | LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of… | |
| Modificada | Media (5.4) | 0.27% | — | Intellectualflame Brightest LED Flashlight | 9/9/2014 | 17/6/2026 | The Brightest LED Flashlight (aka com.intellectualflame.ledflashlight.washer) application 1.2.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Blueflyingfish COM Alameda | 23/8/2012 | 16/6/2026 | SQL injection vulnerability in Alameda (com_alameda) component before 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the storeid parameter to index.php. | |
| Modificada | Alta (7.5) | 0.95% | 💥 Exploit | Joomlame COM Agoragroup | 1/6/2009 | 16/6/2026 | SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php. | |
| Modificada | Media (6.9) | 0.31% | — | Dann Frazier Flamethrower | 18/11/2008 | 16/6/2026 | flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file. |