Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
109 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 4.6% | — | Xiph.org LibvorbisDebian Linux | 21/9/2017 | 17/6/2026 | The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file. | |
| Modificada | Media (6.5) | 1.9% | — | Xiph.org LibvorbisDebian LinuxCanonical Ubuntu Linux | 21/9/2017 | 17/6/2026 | In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis(). | |
| Modificada | Crítica (9.8) | 5.7% | — | Xiph.org LibvorbisDebian LinuxCanonical Ubuntu Linux | 21/9/2017 | 17/6/2026 | Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184. | |
| Modificada | Media (5.5) | 4.8% | 💥 Exploit | Xiph.org Libvorbis | 31/7/2017 | 17/6/2026 | The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file. | |
| Modificada | Media (5.5) | 3.8% | 💥 Exploit | Xiph Vorbis-tools | 31/7/2017 | 17/6/2026 | The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file. | |
| Modificada | Media (4.3) | 4.4% | — | Xiph Vorbis-tools | 21/9/2015 | 17/6/2026 | Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file. | |
| Modificada | Media (5) | 3.2% | — | Xiph Vorbis-toolsOpensuse | 23/1/2015 | 17/6/2026 | oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file. | |
| Modificada | Media (5) | 3.6% | — | Xiph Vorbis-toolsFedoraproject FedoraOpensuse | 23/1/2015 | 17/6/2026 | Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access. | |
| Modificada | Media (5) | 3.6% | — | Fedoraproject FedoraOpensuseXiph Vorbis-tools | 23/1/2015 | 17/6/2026 | oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Orbitscripts Orbit Open AD Server | 11/4/2014 | 17/6/2026 | SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory. | |
| Modificada | Media (6.4) | 1.4% | — | Sebastien Corbin Make Meeting Scheduler Module | 9/10/2013 | 16/6/2026 | The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL. | |
| Modificada | Media (6) | 2.7% | 💥 Exploit | Novo-ws Orbis CMS | 2/12/2010 | 16/6/2026 | Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Novo-ws Orbis CMS | 8/7/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Media (4.3) | 3.0% | — | Orbitdownloader Orbit Downloader | 27/5/2010 | 16/6/2026 | Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Orbitals Orbital Viewer | 19/3/2010 | 16/6/2026 | Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file. | |
| Modificada | Media (5.8) | 3.7% | 💥 Exploit | Orbit DownloaderOrbitdownloader Orbit Downloader | 26/3/2009 | 16/6/2026 | Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method. | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Orbitdownloader Orbit Downloader | 26/2/2009 | 16/6/2026 | Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Orbitscripts SmartppcOrbitscripts Smartppc PRO | 11/7/2008 | 16/6/2026 | SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter. | |
| Modificada | Alta (9.3) | 8.1% | — | Xiph.org Libvorbis | 16/5/2008 | 16/6/2026 | Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow. | |
| Modificada | Media (4.3) | 3.5% | — | Xiph.org LibvorbisCanonical Ubuntu Linux | 16/5/2008 | 16/6/2026 | Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function. | |
| Modificada | Media (4.3) | 4.3% | — | Xiph.org Libvorbis | 16/5/2008 | 16/6/2026 | Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow. | |
| Modificada | Media (6.8) | 6.3% | — | Xiph.org Libvorbis | 16/5/2008 | 16/6/2026 | Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Orbit Downloader | 6/4/2008 | 16/6/2026 | Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed. | |
| Modificada | Media (4.3) | 1.8% | — | Xiph.org Libvorbis | 21/9/2007 | 16/6/2026 | Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the… | |
| Modificada | Media (4.3) | 1.7% | — | Xiph.org Libvorbis | 21/9/2007 | 16/6/2026 | lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217. |