Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 2.5% | — | Videolan VLC Media PlayerOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | Double Free in VLC versions <= 3.0.6 leads to a crash. | |
| Modificada | Alta (7.1) | 2.8% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. | |
| Modificada | Crítica (9.8) | 3.7% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 18/7/2019 | 17/6/2026 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. | |
| Modificada | Media (5.5) | 2.5% | — | Videolan VLC Media Player | 16/7/2019 | 17/6/2026 | libebml before 1.3.6, as used in the MKV module in VideoLAN VLC Media Player binaries before 3.0.3, has a heap-based buffer over-read in EbmlElement::FindNextElement. | |
| Modificada | Alta (7.8) | 2.1% | — | Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 14/7/2019 | 17/6/2026 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file. | |
| Modificada | Crítica (9.8) | 2.4% | — | Videolan VLC Media Player | 18/6/2019 | 17/6/2026 | An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free. | |
| Modificada | Media (6.5) | 5.3% | — | Videolan VLC Media Player | 13/6/2019 | 17/6/2026 | A Buffer Overflow in VLC Media Player < 3.0.7 causes a crash which can possibly be further developed into a remote code execution exploit. | |
| Modificada | Crítica (9.8) | 44% | 💥 Exploit | Gracemedia Media Player Project Gracemedia Media Player | 13/5/2019 | 17/6/2026 | The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. | |
| Modificada | Crítica (9.1) | 3.9% | — | Videolan VLC Media PlayerDebian Linux | 5/12/2018 | 17/6/2026 | The CAF demuxer in modules/demux/caf.c in VideoLAN VLC media player 3.0.4 may read memory from an uninitialized pointer when processing magic cookies in CAF files, because a ReadKukiChunk() cast converts a return value to an unsigned int even if that value is negative. This could result in a denial of service and/or a… | |
| Modificada | Alta (8) | 37% | 💥 Exploit | Debian LinuxVideolan VLC Media Player | 11/7/2018 | 17/6/2026 | VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions. | |
| Modificada | Crítica (9.8) | 8.4% | — | Westerndigital TV Live HUB FirmwareWesterndigital TV Media Player Firmware | 12/6/2018 | 17/6/2026 | The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or cause denial of service via crafted HTTP requests to toServerValue.cgi. | |
| Modificada | Alta (8.8) | 3.7% | — | Videolan VLC Media Player | 28/5/2018 | 17/6/2026 | The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file. | |
| Modificada | Alta (8.8) | 2.2% | — | Videolan VLC Media PlayerDebian Linux | 15/12/2017 | 17/6/2026 | In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation. | |
| Modificada | Baja (2.5) | 6.7% | — | Microsoft Windows Media Player | 15/11/2017 | 17/6/2026 | Windows Media Player in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allows remote attackers to test for the presence of files on disk via a specially crafted… | |
| Modificada | Crítica (9.8) | 4.5% | — | Videolan VLC Media Player | 30/6/2017 | 17/6/2026 | avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution. | |
| Modificada | Alta (7.8) | 2.9% | — | Videolan VLC Media Player | 29/5/2017 | 17/6/2026 | plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid read and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Alta (7.8) | 3.4% | — | Videolan VLC Media Player | 29/5/2017 | 17/6/2026 | plugins\codec\libflac_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted FLAC file. | |
| Modificada | Media (5.5) | 1.5% | — | Videolan VLC Media Player | 23/5/2017 | 17/6/2026 | Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file. | |
| Modificada | Media (5.5) | 1.4% | — | Videolan VLC Media PlayerDebian Linux | 23/5/2017 | 17/6/2026 | Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file. | |
| Modificada | Alta (7.8) | 8.8% | 💥 Exploit | Videolan VLC Media Player | 23/5/2017 | 17/6/2026 | Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an input string allows attackers to execute arbitrary code via a crafted subtitles file. | |
| Modificada | Media (5.5) | 1.3% | — | Videolan VLC Media Player | 23/5/2017 | 17/6/2026 | Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file. | |
| Modificada | Crítica (9.8) | 25% | 💥 Exploit | Debian LinuxVideolan VLC Media Player | 8/6/2016 | 17/6/2026 | Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file. | |
| Modificada | Media (5.5) | 1.3% | — | Videolan VLC Media PlayerCanonical Ubuntu Linux | 18/4/2016 | 17/6/2026 | Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, related to "seek across EOF." | |
| Modificada | Media (6.8) | 13% | — | Videolan VLC Media Player | 25/8/2015 | 17/6/2026 | VideoLAN VLC media player 2.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted 3GP file, which triggers the freeing of arbitrary pointers. | |
| Modificada | Media (4.3) | 1.9% | — | Videolan VLC Media Player | 17/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the httpd_HtmlError function in network/httpd.c in the web interface in VideoLAN VLC Media Player before 2.2.0 allows remote attackers to inject arbitrary web script or HTML via the path info. |