Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3090▲ 519 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
1847 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 4.0% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 29/9/2004 | 16/6/2026 | Directory traversal vulnerability in RealPlayer 10.5 (6.0.12.1040) and earlier allows remote attackers to delete arbitrary files via a Real Metadata Packages (RMP) file with a FILENAME tag containing .. (dot dot) sequences in a filename that ends with a ? (question mark) and an allowed file extension (e.g. .mp3),… | |
| Modificada | Alta (7.5) | 1.8% | — | SMC Networks Smc7004vwbrSMC Networks Smc7008abr | 15/9/2004 | 16/6/2026 | SMC routers SMC7004VWBR running firmware 1.00.014 and SMC7008ABR EU running firmware 1.42.003 allow remote attackers to bypass authentication by connecting to it from the same IP address as the administrator who is logged in, then accessing the setup_status.htm or status.HTM pages. | |
| Modificada | Alta (7.5) | 3.5% | — | Realnetworks Realplayer | 6/8/2004 | 16/6/2026 | Desbordamiento de búfer en Real Networks RealPlayer 10 permite a atacantes remotos ejecutar código de su elección mediante una URL con un número grande de caractéres "." (punto). | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Realnetworks Helix Universal Server | 1/6/2004 | 16/6/2026 | RealNetworks Helix Universal Server 9.0.1 and 9.0.2 allows remote attackers to cause a denial of service (crash) via malformed requests that trigger a null dereference, as demonstrated using (1) GET_PARAMETER or (2) DESCRIBE requests. | |
| Modificada | Media (5.1) | 3.2% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 1/6/2004 | 16/6/2026 | Stack-based buffer overflow in the RT3 plugin, as used in RealPlayer 8, RealOne Player, RealOne Player 10 beta, and RealOne Player Enterprise, allows remote attackers to execute arbitrary code via a malformed .R3T file. | |
| Modificada | Alta (7.5) | 1.5% | — | SMC Networks Smc7004vbr | 28/4/2004 | 16/6/2026 | SMC Barricade broadband router 7008ABR and 7004VBR enable remote administration by default, which allows remote attackers to gain access by connecting to port 1900. | |
| Modificada | Media (6.8) | 1.5% | — | Realnetworks Helix Universal Mobile ServerRealnetworks Helix Universal Server | 17/2/2004 | 16/6/2026 | Helix Universal Server/Proxy 9 y Mobile Server 10 permite a atacantes remotos causar una denegación de servicio mediante ciertos mensajes HTTP POST al puerto de Administración del Sistema. | |
| Modificada | Alta (7.5) | 4.6% | — | Realnetworks Realsystem ProxyRealnetworks Realsystem Server | 31/12/2003 | 16/6/2026 | Buffer overflow in RealSystem Server 6.x, 7.x and 8.x, and RealSystem Proxy 8.x, related to URL error handling, allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Alta (10) | 2.1% | — | Realnetworks Realone Enterprise DesktopRealnetworks Realone Player | 31/12/2003 | 16/6/2026 | Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file before the temp file is executed by the default web browser. | |
| Modificada | Media (5) | 1.8% | — | Efficient Networks 5861 DSL Router | 31/12/2003 | 16/6/2026 | Efficient Networks 5861 DSL router, when running firmware 5.3.80 configured to block incoming TCP SYN, packets allows remote attackers to cause a denial of service (crash) via a flood of TCP SYN packets to the WAN interface using a port scanner such as nmap. | |
| Modificada | Media (5) | 1.9% | — | Point Clark Networks Clarkconnect | 31/12/2003 | 16/6/2026 | clarkconnectd in ClarkConnect Linux 1.2 allows remote attackers to obtain sensitive information about the server via the characters (1) A, which reveals the date and time, (2) F, (3) M, which reveals 'ifconfig' information, (4) P, which lists the processes, (5) Y, which reveals the snort log files, or (6) b, which… | |
| Modificada | Alta (7.5) | 49% | 💥 Exploit | Realnetworks Helix Universal ServerRealnetworks Realserver | 20/10/2003 | 16/6/2026 | Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code. | |
| Modificada | Media (5.1) | 6.8% | 💥 Exploit | Realnetworks Realone Desktop ManagerRealnetworks Realone Enterprise DesktopRealnetworks Realone Player | 20/10/2003 | 16/6/2026 | RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation with a URL that references a scripting protocol, which is executed in the security context of the previously loaded URL, as demonstrated using a "javascript:" URL in the area tag. | |
| Modificada | Media (5) | 1.4% | — | SMC Networks Barricade Wireless Cable DSL Broadband Router | 24/7/2003 | 16/6/2026 | El encaminador de banda ancha inalámbrico para cable y DSL SMC Networks Barricade SMC7004VWBR permite a atacantes remotos causar una denegación de servicio mediante ciertos paquetes al puerto PPTP 1723 en el interfaz interno. | |
| Modificada | Alta (7.5) | 4.1% | — | Sharman Networks Kazaa | 2/7/2003 | 16/6/2026 | Desbordamiento de búfer en el código de red FastTrack (FT), usada en Kazaa 2.0.2 y posiblemente otras versiones y productos, permite a atacantes remotos ejecutar código arbitrario mediante un paquete conteniendo una lista de supernodos larga, también conocido como Packet 0' death | |
| Modificada | Media (5.1) | 3.0% | — | Realnetworks Realone Enterprise DesktopRealnetworks Realone PlayerRealnetworks Realplayer | 2/4/2003 | 16/6/2026 | The PNG deflate algorithm in RealOne Player 6.0.11.x and earlier, RealPlayer 8/RealPlayer Plus 8 6.0.9.584, and other versions allows remote attackers to corrupt the heap and overwrite arbitrary memory via a PNG graphic file format containing compressed data using fixed trees that contain the length values 286-287,… | |
| Modificada | Media (5) | 1.8% | — | Summit Computer Networks LIL Http | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Lil' HTTP server 2.1 and 2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request. | |
| Modificada | Alta (7.5) | 75% | 💥 Exploit | Realnetworks Helix Universal Server | 19/12/2002 | 16/6/2026 | Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments. | |
| Modificada | Alta (7.5) | 3.3% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 11/12/2002 | 16/6/2026 | Mültiples desbordamientos de búfer en RealOne y RealPlayer permite a atacantes remotos ejecutar código arbitrario mediante un fichero de Lenguaje de Integración Multimedia Sincronizada (SMIL) con un parámetro largo. un nombre de fichero largo en una petición rtsp://, por ejemplo un fichero. m3u, o Ciertas opciones… | |
| Modificada | Alta (7.5) | 2.0% | — | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by… | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Summit Computer Networks LIL Http Server | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters. | |
| Modificada | Alta (7.5) | 7.1% | 💥 Exploit | Summit Computer Networks LIL Http Server | 4/10/2002 | 16/6/2026 | Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image. | |
| Modificada | Baja (1.7) | 1.3% | — | Realnetworks Realplayer | 12/8/2002 | 16/6/2026 | Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275. | |
| Modificada | Media (5) | 1.7% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. |