Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

100 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)4.1%—Adobe Flash Media Server21/12/200916/6/2026
Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.
ModificadaAlta (7.5)2.6%—Adobe Flash Media Server21/12/200916/6/2026
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors.
ModificadaAlta (7.5)3.3%—Adobe Flash Media Server1/5/200916/6/2026
Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.
ModificadaMedia (5)2.3%—Adobe Flash Media Server25/11/200816/6/2026
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of video content via stream-capture software.
ModificadaAlta (10)4.6%—Adobe Connect Enterprise ServerAdobe Flash Media Server 213/2/200816/6/2026
Unspecified vulnerability in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to "take control of the affected system" via unspecified vectors, a different issue than CVE-2007-6148 and CVE-2007-6149.
ModificadaAlta (10)8.4%—Adobe Connect Enterprise ServerAdobe Flash Media Server 213/2/200816/6/2026
Use-after-free vulnerability in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to execute arbitrary code via an unspecified sequence of Real Time Message Protocol (RTMP) requests.
ModificadaAlta (10)12%—Adobe Connect Enterprise ServerAdobe Flash Media Server 213/2/200816/6/2026
Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.
ModificadaAlta (7.1)4.4%💥 ExploitLive555 Media Server20/11/200716/6/2026
The parseRTSPRequestString function in LIVE555 Media Server 2007.11.01 and earlier allows remote attackers to cause a denial of service (daemon crash) via a short RTSP query, which causes a negative number to be used during memory allocation.
ModificadaAlta (7.1)5.6%💥 ExploitFirefly Media Server5/11/200716/6/2026
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line…
ModificadaAlta (7.5)3.7%—Firefly Media Server5/11/200716/6/2026
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the…
ModificadaAlta (9.3)17%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XPAvaya Media Server+330/4/200716/6/2026
Unspecified vulnerability in Microsoft Windows 2000, XP, and Server 2003 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. NOTE: this information is based upon a vague pre-advisory with no actionable information. However, the advisory is from a reliable source.
ModificadaAlta (9.3)55%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows VistaMicrosoft Windows XP+630/3/200716/6/2026
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416,…
ModificadaMedia (5)1.8%—Sony Vaio Media Server22/8/200616/6/2026
Directory traversal vulnerability in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to gain sensitive information via unspecified vectors.
ModificadaAlta (10)6.1%—Sony Vaio Media Server22/8/200616/6/2026
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.8)4.2%💥 ExploitMacromedia Flash Media Server14/12/200516/6/2026
The Administration Service (FMSAdmin.exe) in Macromedia Flash Media Server 2.0 r1145 allows remote attackers to cause a denial of service (application crash) via a malformed request with a single character to port 1111.
ModificadaMedia (5)3.4%💥 ExploitInnovateware Sights N Sounds Streaming Media Server13/12/200516/6/2026
Buffer overflow in MediaServerList.exe in Sights 'n Sounds Streaming Media Server 2.0.3.a allows remote attackers to cause a denial of service (application crash) via a long query string.
ModificadaAlta (10)67%💥 ExploitAvaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+331/12/200416/6/2026
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
ModificadaBaja (2.1)0.34%—Keene Digital Media ServerAI31/12/200416/6/2026
Keene Digital Media Server 1.0.2 allows local users to obtain usernames and passwords by reading the dmscore.db file on the local system.
ModificadaMedia (5)49%💥 ExploitAvaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+323/12/200416/6/2026
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
ModificadaAlta (7.5)57%💥 ExploitAvaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+323/12/200416/6/2026
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "<STYLE>@;/*" string,…
ModificadaMedia (5)34%—Avaya Ip600 Media ServersMicrosoft IEMicrosoft Internet ExplorerAvaya Definity ONE Media Server+1418/8/200416/6/2026
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by…
ModificadaMedia (5)16%—Avaya Ip600 Media ServersMicrosoft Outlook ExpressAvaya Definity ONE Media ServerAvaya S8100+16/8/200416/6/2026
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
ModificadaAlta (10)64%💥 ExploitAvaya Ip600 Media ServersMicrosoft IEAvaya Definity ONE Media ServerAvaya S8100+46/8/200416/6/2026
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
ModificadaAlta (7.2)24%—Avaya Ip600 Media ServersMicrosoft Internet Information ServerAvaya Definity ONE Media ServerAvaya S8100+16/8/200416/6/2026
Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.
ModificadaAlta (10)45%—Avaya Ip600 Media ServersAvaya Definity ONE Media ServerAvaya S8100Avaya Modular Messaging Message Storage Server+76/8/200416/6/2026
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
Orbitaley — Vulnerabilidades