Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a direct copy to NULL pointer dereference, leading to a denial of service (DOS). | |
| Modificada | Media (6.5) | 1.2% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | A heap buffer overflow vulnerability in Ap4TrunAtom.cpp of Bento 1.5.1-628 may lead to an out-of-bounds write while running mp42aac, leading to system crashes and a denial of service (DOS). | |
| Modificada | Media (6.5) | 1.0% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS). | |
| Modificada | Media (6.5) | 5.7% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | A buffer overflow vulnerability in Ap4ElstAtom.cpp of Bento 1.5.1-628 leads to a denial of service (DOS). | |
| Modificada | Media (6.5) | 1.0% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | An unhandled memory allocation failure in Core/Ap4Atom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS). | |
| Modificada | Media (6.5) | 0.98% | — | Axiosys Bento4 | 13/7/2021 | 17/6/2026 | An unhandled memory allocation failure in Core/Ap48bdlAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS). | |
| Modificada | Media (5.5) | 0.72% | — | Axiosys Bento4 | 21/4/2021 | 17/6/2026 | An issue was discovered in Bento4 through v1.6.0-637. A NULL pointer dereference exists in the function AP4_StszAtom::GetSampleSize() located in Ap4StszAtom.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.1) | 1.4% | — | Rosariosis Student Information System | 12/8/2020 | 17/6/2026 | Reflected Cross-Site Scripting vulnerability in Modules.php in RosarioSIS Student Information System < 6.5.1 allows remote attackers to execute arbitrary web script via embedding javascript or HTML tags in a GET request. | |
| Modificada | Media (6.1) | 6.4% | 💥 Exploit | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the PrintSchedules.php script. A remote attacker could exploit this vulnerability using the include_inactive parameter in a crafted URL. | |
| Modificada | Media (6.1) | 1.5% | — | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Search.inc.php script. A remote attacker could exploit this vulnerability using the advanced parameter in a crafted URL. | |
| Modificada | Media (6.1) | 5.6% | 💥 Exploit | Rosariosis | 15/7/2020 | 17/6/2026 | RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php script. A remote attacker could exploit this vulnerability using the tab parameter in a crafted URL. | |
| Modificada | Media (6.1) | 1.5% | — | Rosariosis | 14/7/2020 | 17/6/2026 | RosarioSIS through 6.8-beta allows modules/Custom/NotifyParents.php XSS because of the href attributes for AddStudents.php and User.php. | |
| Modificada | Alta (7.5) | 2.5% | — | Bytemark Symbiosis | 27/1/2020 | 17/6/2026 | Bytemark Symbiosis allows remote attackers to cause a denial of service via a crafted username, which triggers the firewall to blacklist the IP. | |
| Modificada | Media (5.5) | 0.78% | — | Axiosys Bento4 | 30/12/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_EsDescriptor::GetDecoderConfigDescriptor in Ap4EsDescriptor.cpp. | |
| Modificada | Media (5.5) | 0.78% | — | Axiosys Bento4 | 30/12/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a NULL pointer dereference in AP4_Descriptor::GetTag in mp42ts when called from AP4_DecoderConfigDescriptor::GetDecoderSpecificInfoDescriptor in Ap4DecoderConfigDescriptor.cpp. | |
| Modificada | Alta (7.8) | 0.82% | — | Axiosys Bento4 | 30/12/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a use-after-free in AP4_Sample::GetOffset in Core/Ap4Sample.h when called from Ap4LinearReader.cpp. | |
| Modificada | Alta (7.8) | 0.53% | — | Axiosys Bento4 | 12/10/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_PrintInspector::AddField in Core/Ap4Atom.cpp when called from AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp, when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp. | |
| Modificada | Alta (7.8) | 0.53% | — | Axiosys Bento4 | 12/10/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in AP4_CencSampleEncryption::DoInspectFields in Core/Ap4CommonEncryption.cpp when called from AP4_Atom::Inspect in Core/Ap4Atom.cpp. | |
| Modificada | Alta (7.5) | 1.1% | — | Axiosys Bento4 | 12/10/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a SEGV in the function AP4_TfhdAtom::SetDefaultSampleSize at Core/Ap4TfhdAtom.h when called from AP4_Processor::ProcessFragments in Core/Ap4Processor.cpp. | |
| Modificada | Media (6.5) | 1.2% | — | Axiosys Bento4 | 10/10/2019 | 17/6/2026 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_Descriptor::GetTag in Core/Ap4Descriptor.h, related to AP4_StsdAtom::GetSampleDescription in Core/Ap4StsdAtom.cpp, as demonstrated by mp4info. | |
| Modificada | Media (6.5) | 1.2% | — | Axiosys Bento4 | 10/10/2019 | 17/6/2026 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListWriter::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::WriteFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4encrypt or mp4compact. | |
| Modificada | Media (6.5) | 1.1% | — | Axiosys Bento4 | 10/10/2019 | 17/6/2026 | Bento4 1.5.1.0 has a NULL pointer dereference in AP4_DescriptorListInspector::Action in Core/Ap4Descriptor.h, related to AP4_IodsAtom::InspectFields in Core/Ap4IodsAtom.cpp, as demonstrated by mp4dump. | |
| Modificada | Media (5.5) | 0.85% | — | Axiosys Bento4 | 16/9/2019 | 17/6/2026 | Bento4 1.5.1-628 has a NULL pointer dereference in AP4_ByteStream::ReadUI32 in Core/Ap4ByteStream.cpp when called from the AP4_TrunAtom class. | |
| Modificada | Alta (8.8) | 1.5% | — | Axiosys Bento4 | 14/8/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_AvccAtom class at Core/Ap4AvccAtom.cpp. | |
| Modificada | Alta (8.8) | 1.5% | — | Axiosys Bento4 | 14/8/2019 | 17/6/2026 | An issue was discovered in Bento4 1.5.1.0. There is a heap-based buffer over-read in the AP4_Dec3Atom class at Core/Ap4Dec3Atom.cpp. |