Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
173 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 0.91% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/6/2005 | 16/6/2026 | RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers". | |
| Modificada | Media (5.1) | 1.5% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/6/2005 | 16/6/2026 | Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file. | |
| Modificada | Media (5.1) | 4.1% | — | Realnetworks Realplayer | 28/6/2005 | 16/6/2026 | Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file. | |
| Modificada | Media (5.1) | 2.2% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 28/6/2005 | 16/6/2026 | Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value. | |
| Modificada | Media (5.1) | 3.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files. | |
| Modificada | Media (5.1) | 54% | 💥 Exploit | Realnetworks RealplayerAIRealnetworks Realone PlayerAI | 2/5/2005 | 16/6/2026 | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value. | |
| Modificada | Media (5.1) | 3.4% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 19/4/2005 | 16/6/2026 | Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file. | |
| Modificada | Media (5.1) | 3.4% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 19/1/2005 | 16/6/2026 | Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag. | |
| Modificada | Alta (10) | 9.6% | — | Checkmark PayrollCheckmark MultiledgerInnermedia Dynazip LibraryRealnetworks Realone Player+1 | 10/1/2005 | 16/6/2026 | Buffer overflow in InnerMedia DynaZip DUNZIP32.dll file version 5.00.03 and earlier allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, as demonstrated using (1) a .rjs (skin) file in RealPlayer 10 through RealPlayer 10.5 (6.0.12.1053), RealOne Player 1 and 2, (2)… | |
| Modificada | Media (5.1) | 4.3% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 31/12/2004 | 16/6/2026 | Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow. | |
| Modificada | Media (5.1) | 2.2% | — | Realnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 31/12/2004 | 16/6/2026 | RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than… | |
| Modificada | Alta (7.6) | 7.2% | — | Realnetworks Realone Desktop ManagerRealnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 23/11/2004 | 16/6/2026 | Multiple buffer overflows in RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, and RealPlayer Enterprise allow remote attackers to execute arbitrary code via malformed (1) .RP, (2) .RT, (3) .RAM, (4) .RPM or (5) .SMIL files. | |
| Modificada | Baja (2.6) | 2.0% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 6/10/2004 | 16/6/2026 | Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename. | |
| Modificada | Alta (7.5) | 6.4% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 6/10/2004 | 16/6/2026 | Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument. | |
| Modificada | Baja (2.6) | 4.0% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/9/2004 | 16/6/2026 | Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3),… | |
| Modificada | Alta (7.5) | 3.5% | — | Realnetworks Realplayer | 6/8/2004 | 16/6/2026 | Buffer overflow in Real Networks RealPlayer 10 allows remote attackers to execute arbitrary code via a URL with a large number of "." (period) characters. | |
| Modificada | Media (5.1) | 3.2% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 1/6/2004 | 16/6/2026 | Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file. | |
| Modificada | Media (5.1) | 3.0% | — | Realnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 2/4/2003 | 16/6/2026 | The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287,… | |
| Modificada | Alta (7.5) | 3.3% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 11/12/2002 | 16/6/2026 | Multiple buffer overflows in RealOne and RealPlayer allow remote attackers to execute arbitrary code via (1) a Synchronized Multimedia Integration Language (SMIL) file with a long parameter, (2) a long long filename in a rtsp:// request, e.g. from a .m3u file, or (3) certain "Now Playing" options on a downloaded file… | |
| Modificada | Baja (1.7) | 1.3% | — | Realnetworks Realplayer | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275. | |
| Modificada | Media (5.4) | 1.6% | — | Realnetworks Realplayer | 25/6/2002 | 16/6/2026 | RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Realnetworks Realone PlayerRealnetworks Realplayer Intranet | 16/5/2002 | 16/6/2026 | Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a header length value that exceeds the actual length of the header. | |
| Modificada | Baja (2.6) | 4.6% | 💥 Exploit | Realnetworks Realplayer | 3/4/2000 | 16/6/2026 | Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL. |