Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

223 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)13%💥 ExploitVideolan VLC Media Player26/8/201016/6/2026
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .mp3 file.
ModificadaMedia (5)2.6%—Videolan VLC Media Player20/8/201016/6/2026
The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.
ModificadaMedia (6.8)3.0%—Bestwebsharing Groovy Media Player12/7/201016/6/2026
Stack-based buffer overflow in Groovy Media Player 1.1.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.
ModificadaAlta (9.3)5.8%💥 ExploitUltraplayer Media Player11/5/201016/6/2026
Stack-based buffer overflow in UltraPlayer Media Player 2.112 allows remote attackers to execute arbitrary code via a long string in a .usk file.
ModificadaAlta (9.3)20%—Microsoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows XP14/4/201016/6/2026
Unspecified vulnerability in the Windows Media Player ActiveX control in Windows Media Player (WMP) 9 on Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted media content, aka "Media Player Remote Code Execution Vulnerability."
ModificadaMedia (4.3)10%💥 ExploitMicrosoft Windows Media Player23/3/201016/6/2026
Microsoft Windows Media Player 11 does not properly perform colorspace conversion, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .AVI file. NOTE: the provenance of this information is unknown; the details are obtained solely from third…
ModificadaAlta (8.5)2.9%—Cisco Digital Media PlayerCisco Digital Media Player 4300gCisco Digital Media Player 4305gCisco Digital Media Player 4400g5/3/201016/6/2026
Unspecified vulnerability on the Cisco Digital Media Player before 5.2 allows remote attackers to hijack the source of (1) video or (2) data for a display via unknown vectors, related to a "content injection" issue, aka Bug ID CSCtc46024.
ModificadaMedia (4.3)8.8%💥 ExploitMicrosoft Windows Media Player26/2/201016/6/2026
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted .mpg file.
ModificadaAlta (9.3)6.6%💥 ExploitVideolan VLC Media Player21/1/201016/6/2026
Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.
ModificadaAlta (9.3)4.4%💥 ExploitCdmi A2 Media Player PRO4/1/201016/6/2026
Stack-based buffer overflow in A2 Media Player Pro 2.51 allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .m3l playlist file.
ModificadaAlta (9.3)24%—Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XPWindows Media Player13/12/200916/6/2026
Stack-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted compressed video data in an IV41 stream in a media file, leading to many loop iterations, as demonstrated by…
ModificadaAlta (9.3)24%—Microsoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows XP13/12/200916/6/2026
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file.
ModificadaAlta (9.3)27%—Microsoft Windows Media Player14/10/200916/6/2026
Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka "WMP Heap Overflow Vulnerability."
ModificadaAlta (9.3)23%—Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+314/10/200916/6/2026
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2)…
ModificadaAlta (9.3)27%—Microsoft Windows 2000Microsoft Windows Media Format RuntimeMicrosoft Windows Media PlayerMicrosoft Windows XP+314/10/200916/6/2026
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media…
ModificadaAlta (9.3)35%💥 ExploitPirateradio Destiny Media Player25/9/200916/6/2026
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.
ModificadaMedia (4.3)1.9%💥 ExploitROB Schultz Media Player Classic15/9/200916/6/2026
Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.
ModificadaAlta (9.3)35%💥 ExploitVideolan VLC Media Player16/7/200916/6/2026
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.
ModificadaAlta (9.3)18%💥 ExploitMicrosoft Windows Media Player17/4/200916/6/2026
Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.
ModificadaMedia (5)9.2%💥 ExploitVideolan VLC Media Player23/3/200916/6/2026
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action.
ModificadaAlta (9.3)10%💥 ExploitMerak Media Player29/1/200916/6/2026
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party information.
ModificadaAlta (9.3)4.5%💥 ExploitTrilogic Media Player26/1/200916/6/2026
Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (9.3)6.2%💥 ExploitTrilogic Media Player23/1/200916/6/2026
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)21%💥 ExploitMicrosoft Windows Media Player29/12/200816/6/2026
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a…
ModificadaAlta (9.3)36%💥 ExploitRealtek Media Player19/12/200816/6/2026
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted playlist (PLA) file.
Orbitaley — Vulnerabilidades