Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 46% | 💥 Exploit | Realnetworks Realplayer | 12/3/2008 | 16/6/2026 | The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1) Console or (2) Controls property, which allows remote attackers to… | |
| Modificada | Alta (10) | 5.5% | — | Realnetworks Realplayer | 8/1/2008 | 16/6/2026 | Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for… | |
| Modificada | Media (5) | 1.5% | — | Realnetworks Realplayer | 4/12/2007 | 16/6/2026 | The RealNetworks RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll, as shipped with RealPlayer 11, allows remote attackers to cause a denial of service (browser crash) via a certain argument to the GetSourceTransport method. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Realnetworks Realplayer | 4/12/2007 | 16/6/2026 | A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. NOTE: this might be related to CVE-2007-4904. | |
| Modificada | Alta (9.3) | 8.4% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 31/10/2007 | 16/6/2026 | Stack-based buffer overflow in RealNetworks RealPlayer 10 and possibly 10.5, and RealOne Player 1 and 2, for Windows allows remote attackers to execute arbitrary code via a crafted playlist (PLS) file. | |
| Modificada | Alta (9.3) | 7.3% | — | Realnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 31/10/2007 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a RAM (.ra or .ram) file with a large size value in the RA header. | |
| Modificada | Alta (9.3) | 5.4% | — | Realnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 31/10/2007 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 8, 10, 10.1, and possibly 10.5; RealOne Player 1 and 2; and RealPlayer Enterprise allows remote attackers to execute arbitrary code via a crafted RM file. | |
| Modificada | Alta (9.3) | 7.3% | — | Realnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 31/10/2007 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 10.0, 10.1, and possibly 10.5, RealOne Player, and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an SWF (Flash) file with malformed record headers. | |
| Modificada | Alta (9.3) | 7.7% | — | Realnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 31/10/2007 | 16/6/2026 | Integer overflow in RealNetworks RealPlayer 10 and 10.5, RealOne Player 1, and RealPlayer Enterprise for Windows allows remote attackers to execute arbitrary code via a crafted Lyrics3 2.00 tag in an MP3 file, resulting in a heap-based buffer overflow. | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Realnetworks Realplayer | 20/10/2007 | 16/6/2026 | Stack-based buffer overflow in the Database Component in MPAMedia.dll in RealNetworks RealPlayer 10.5 and 11 beta, and earlier versions including 10, RealOne Player, and RealOne Player 2, allows remote attackers to execute arbitrary code via certain playlist names, as demonstrated via the import method to the IERPCtl… | |
| Modificada | Media (4.3) | 2.8% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realplayer | 17/9/2007 | 16/6/2026 | RealNetworks RealPlayer 10.1.0.3114 and earlier, and Helix Player 1.0.6.778 on Fedora Core 6 (FC6) and possibly other platforms, allow user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. | |
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Realplayer Enterprise | 26/6/2007 | 16/6/2026 | Stack-based buffer overflow in the SmilTimeValue::parseWallClockValue function in smlprstime.cpp in RealNetworks RealPlayer 10, 10.1, and possibly 10.5, RealOne Player, RealPlayer Enterprise, and Helix Player 10.5-GOLD and 10.0.5 through 10.0.8, allows remote attackers to execute arbitrary code via an SMIL (SMIL2)… | |
| Modificada | Alta (7.8) | 7.1% | 💥 Exploit | Realnetworks Realplayer | 4/5/2007 | 16/6/2026 | RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain .ra file. NOTE: this issue was referred to as a "memory leak," but it is not clear if this is correct. | |
| Modificada | Media (5) | 6.4% | 💥 Exploit | Realnetworks Realplayer | 31/12/2006 | 16/6/2026 | An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) by invoking the RealPlayer.OpenURLInPlayerBrowser method with a long second argument. | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Realnetworks Realplayer | 27/12/2006 | 16/6/2026 | A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service (Internet Explorer crash) by invoking the RealPlayer.Initialize method with certain arguments. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 23/3/2006 | 16/6/2026 | Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified… | |
| Modificada | Alta (9.3) | 2.9% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 23/3/2006 | 16/6/2026 | Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file. | |
| Modificada | Alta (9.3) | 5.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which… | |
| Modificada | Alta (7.5) | 1.8% | — | Realnetworks Realplayer | 9/12/2005 | 16/6/2026 | ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not… | |
| Modificada | Alta (7.5) | 2.2% | — | Realnetworks Realplayer | 9/12/2005 | 16/6/2026 | ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows remote attackers to execute arbitrary code. NOTE: it is not known whether this issue should be MERGED with… | |
| Modificada | Alta (7.5) | 3.3% | — | Realnetworks Realplayer | 18/11/2005 | 16/6/2026 | Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different. | |
| Modificada | Media (5.1) | 4.5% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability… | |
| Modificada | Alta (7.2) | 3.3% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realplayer | 27/9/2005 | 16/6/2026 | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file. |