Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3089▲ 499 respecto a la semana anterior
Críticas / altas1463▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1847 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 1.5% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/6/2005 | 16/6/2026 | Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file. | |
| Modificada | Media (5) | 0.91% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/6/2005 | 16/6/2026 | RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers". | |
| Modificada | Media (5.1) | 2.2% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 28/6/2005 | 16/6/2026 | Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value. | |
| Modificada | Media (5.1) | 4.1% | — | Realnetworks Realplayer | 28/6/2005 | 16/6/2026 | Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Media (4.6) | 0.85% | — | Extremenetworks Extremeware XOS | 19/5/2005 | 16/6/2026 | Unknown vulnerability in Extreme BlackDiamond 10808 and 8800 switches running ExtremeWare XOS 11.1 before 11.1.3.3, 11.0 before 11.0.2.4, and 10.x allows remote authenticated users to execute arbitrary commands. | |
| Modificada | Media (5.1) | 54% | 💥 Exploit | Realnetworks RealplayerAIRealnetworks Realone PlayerAI | 2/5/2005 | 16/6/2026 | Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value. | |
| Modificada | Media (5.1) | 3.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files. | |
| Modificada | Baja (2.6) | 1.4% | — | Realnetworks Realarcade | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in RealArcade 1.2.0.994 allows remote attackers to delete arbitrary files via an RGP file with a .. (dot dot) in the FILENAME tag. | |
| Modificada | Alta (7.5) | 1.3% | — | Barracuda Networks Barracuda Spam Firewall | 2/5/2005 | 16/6/2026 | Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam. | |
| Modificada | Alta (7.5) | 1.8% | — | Powertech Powerlock Networksecurity | 20/4/2005 | 16/6/2026 | Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. | |
| Modificada | Media (5.1) | 3.4% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 19/4/2005 | 16/6/2026 | Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file. | |
| Modificada | Media (5.1) | 3.4% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 19/1/2005 | 16/6/2026 | Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag. | |
| Modificada | Alta (10) | 9.6% | — | Checkmark PayrollCheckmark MultiledgerInnermedia Dynazip LibraryRealnetworks Realone Player+1 | 10/1/2005 | 16/6/2026 | Desbordamiento de búfer en el archivo InnerMedia DynaZip DUNZIP32.dll versión 5.00.03 y anteriores permite a atacantes ejecutar código de su elección mediante un fichero ZIP con un nombre de fichero largo, como se a demostrado usando (1) un fichero .rjs (piel) en RealPlayer 10 a 10.5 (6.0.12.1053) y RealOne Player 1 y… | |
| Modificada | Media (5.1) | 2.2% | — | Realnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 31/12/2004 | 16/6/2026 | RealOne player 6.0.11.868 allows remote attackers to execute arbitrary script in the "My Computer" zone via a Synchronized Multimedia Integration Language (SMIL) presentation with a "file:javascript:" URL, which is executed in the security context of the previously loaded URL, a different vulnerability than… | |
| Modificada | Media (5.8) | 0.79% | — | Peersec Networks Matrixssl | 31/12/2004 | 16/6/2026 | PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms… | |
| Modificada | Media (5.1) | 4.3% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 31/12/2004 | 16/6/2026 | Integer overflow in pnen3260.dll in RealPlayer 8 through 10.5 (6.0.12.1040) and earlier, and RealOne Player 1 or 2 on Windows or Mac OS, allows remote attackers to execute arbitrary code via a SMIL file and a .rm movie file with a large length field for the data chunk, which leads to a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 1.2% | — | Peersec Networks Matrixssl | 31/12/2004 | 16/6/2026 | PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session. | |
| Modificada | Media (5.1) | 1.9% | — | Realnetworks RealoneAIMicrosoft Internet ExplorerAI | 31/12/2004 | 16/6/2026 | pnxr3260.dll in the RealOne 2.0 build 6.0.11.868 browser plugin, as used in Internet Explorer, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embed tag. | |
| Modificada | Alta (7.5) | 1.4% | 💥 Exploit | IP3 Networks IP3 NetaccessIP3 Networks IP3 Netaccess - HospitalityIP3 Networks IP3 Netaccess - Wireless Hotspots | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to bypass authentication via the (1) login or (2) password. NOTE: this issue was later reported to also affect firmware 4.0.34. | |
| Modificada | Alta (7.6) | 7.2% | — | Realnetworks Realone Desktop ManagerRealnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 23/11/2004 | 16/6/2026 | Múltiples desbordamientos de búfer en RealOne Player, RealOne Player 2.0, RealOne Enterprise Desktop, y RealPlayer Enterprise permiten a atacantes remotos ejecutar código de su elección mediante ficheros 1) .RP, (2) .RT, (3) .RAM, (4) .RPM o (5) .SMIL malformados. | |
| Modificada | Alta (9.3) | 4.0% | — | Realnetworks Realone Desktop ManagerRealnetworks Realone Enterprise DesktopRealnetworks Realone Player | 23/11/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en RealOne Player, RealOne Player 2.0, y RealOne Enterprise Desktop permite a atacantes remotos subir ficheros arbitrarios mediante un fichero RMP que contenga secuencias .. (punto punto) en fichero de piel .rjs. | |
| Modificada | Alta (7.8) | 1.9% | — | Realnetworks Helix Universal Mobile Server AND GatewayRealnetworks Helix Universal Server | 3/11/2004 | 16/6/2026 | RealNetworks Helix Universal Server 9.0.2 para Linux y 9.0.3 for Windows permite a atacantes remotos causar una denegación de servicio (consumición de memoria y CPU) mediante peticiones POST con una cabecera Content-Length puesta a -1. | |
| Modificada | Baja (2.6) | 2.0% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 6/10/2004 | 16/6/2026 | Directory traversal vulnerability in the parsing of Skin file names in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in an RJS filename. | |
| Modificada | Alta (7.5) | 6.4% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 6/10/2004 | 16/6/2026 | Stack-based buffer overflow in the HandleAction function in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to execute arbitrary code via a long ShowPreferences argument. |