Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

109 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.6%—Xiph.org LibvorbisDebian Linux21/9/201717/6/2026
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.
ModificadaMedia (6.5)1.9%—Xiph.org LibvorbisDebian LinuxCanonical Ubuntu Linux21/9/201717/6/2026
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().
ModificadaCrítica (9.8)5.7%—Xiph.org LibvorbisDebian LinuxCanonical Ubuntu Linux21/9/201717/6/2026
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.
ModificadaMedia (5.5)4.8%💥 ExploitXiph.org Libvorbis31/7/201717/6/2026
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
ModificadaMedia (5.5)3.8%💥 ExploitXiph Vorbis-tools31/7/201717/6/2026
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
ModificadaMedia (4.3)4.4%—Xiph Vorbis-tools21/9/201517/6/2026
Buffer overflow in the aiff_open function in oggenc/audio.c in vorbis-tools 1.4.0 and earlier allows remote attackers to cause a denial of service (crash) via a crafted AIFF file.
ModificadaMedia (5)3.2%—Xiph Vorbis-toolsOpensuse23/1/201517/6/2026
oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.
ModificadaMedia (5)3.6%—Xiph Vorbis-toolsFedoraproject FedoraOpensuse23/1/201517/6/2026
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
ModificadaMedia (5)3.6%—Fedoraproject FedoraOpensuseXiph Vorbis-tools23/1/201517/6/2026
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
ModificadaAlta (7.5)1.2%💥 ExploitOrbitscripts Orbit Open AD Server11/4/201417/6/2026
SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitrary SQL commands via the site_directory_sort_field parameter to guest/site_directory.
ModificadaMedia (6.4)1.4%—Sebastien Corbin Make Meeting Scheduler Module9/10/201316/6/2026
The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a direct request to the node's URL instead of the hashed URL.
ModificadaMedia (6)2.7%💥 ExploitNovo-ws Orbis CMS2/12/201016/6/2026
Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/.
ModificadaMedia (4.3)1.5%💥 ExploitNovo-ws Orbis CMS8/7/201016/6/2026
Cross-site scripting (XSS) vulnerability in admin/editors/text/editor-body.php in Orbis CMS 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaMedia (4.3)3.0%—Orbitdownloader Orbit Downloader27/5/201016/6/2026
Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element.
ModificadaAlta (9.3)38%💥 ExploitOrbitals Orbital Viewer19/3/201016/6/2026
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a crafted (1) .orb or (2) .ov file.
ModificadaMedia (5.8)3.7%💥 ExploitOrbit DownloaderOrbitdownloader Orbit Downloader26/3/200916/6/2026
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.
ModificadaAlta (9.3)40%💥 ExploitOrbitdownloader Orbit Downloader26/2/200916/6/2026
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.
ModificadaAlta (7.5)1.1%💥 ExploitOrbitscripts SmartppcOrbitscripts Smartppc PRO11/7/200816/6/2026
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary SQL commands via the idDirectory parameter.
ModificadaAlta (9.3)8.1%—Xiph.org Libvorbis16/5/200816/6/2026
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted OGG file with a large virtual space for its codebook, which triggers a heap overflow.
ModificadaMedia (4.3)3.5%—Xiph.org LibvorbisCanonical Ubuntu Linux16/5/200816/6/2026
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tree function.
ModificadaMedia (4.3)4.3%—Xiph.org Libvorbis16/5/200816/6/2026
Xiph.org libvorbis 1.2.0 and earlier does not properly handle a zero value for codebook.dim, which allows remote attackers to cause a denial of service (crash or infinite loop) or trigger an integer overflow.
ModificadaMedia (6.8)6.3%—Xiph.org Libvorbis16/5/200816/6/2026
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbitrary code via a crafted OGG file, which triggers a heap overflow.
ModificadaAlta (10)67%💥 ExploitOrbit Downloader6/4/200816/6/2026
Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.
ModificadaMedia (4.3)1.8%—Xiph.org Libvorbis21/9/200716/6/2026
Multiple buffer overflows in Xiph.Org libvorbis before 1.2.0 allow context-dependent attackers to cause a denial of service or have other unspecified impact via a crafted OGG file, aka trac Changesets 13162, 13168, 13169, 13170, 13172, 13211, and 13215, as demonstrated by an overflow in oggenc.exe related to the…
ModificadaMedia (4.3)1.7%—Xiph.org Libvorbis21/9/200716/6/2026
lib/vorbisfile.c in libvorbisfile in Xiph.Org libvorbis before 1.2.0 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted OGG file, aka trac Changeset 13217.
Orbitaley — Vulnerabilidades