Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 6.9% | — | Apple Quicktime | 4/4/2008 | 16/6/2026 | Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file with Kodak encoding, related to error checking and error messages. | |
| Modificada | Alta (7.5) | 9.2% | 💥 Exploit | Apple Quicktime | 14/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix… | |
| Modificada | Media (5.8) | 3.8% | — | Apple Quicktime | 16/1/2008 | 16/6/2026 | Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption. | |
| Modificada | Alta (9.3) | 5.4% | — | Apple Quicktime | 16/1/2008 | 16/6/2026 | Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption. | |
| Modificada | Media (6.8) | 4.6% | — | Apple Quicktime | 16/1/2008 | 16/6/2026 | Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding. | |
| Modificada | Media (5.8) | 3.0% | — | Apple Quicktime | 16/1/2008 | 16/6/2026 | Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Apple Quicktime | 11/1/2008 | 16/6/2026 | Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message. | |
| Modificada | Alta (9.3) | 4.0% | — | Apple Quicktime | 15/12/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in the Flash media handler in Apple QuickTime before 7.3.1 allow remote attackers to execute arbitrary code or have other unspecified impacts via a crafted QuickTime movie. | |
| Modificada | Media (6.8) | 3.1% | — | Apple Quicktime | 15/12/2007 | 16/6/2026 | Heap-based buffer overflow in Apple QuickTime before 7.3.1 allows remote attackers to execute arbitrary code via a crafted QTL file. | |
| Modificada | Alta (10) | 3.9% | — | Apple Quicktime | 4/12/2007 | 16/6/2026 | Unspecified vulnerability in Apple QuickTime 7.2 on Windows XP allows remote attackers to execute arbitrary code via unknown attack vectors, probably a different vulnerability than CVE-2007-6166. NOTE: this information is based upon a vague advisory by a vulnerability information sales organization that does not… | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Apple QuicktimeApple Safari | 29/11/2007 | 16/6/2026 | Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header. | |
| Modificada | Media (6.8) | 3.7% | — | Apple Quicktime | 27/11/2007 | 16/6/2026 | An "integer arithmetic" error in Apple QuickTime 7.2 allows remote attackers to execute arbitrary code via a crafted movie file containing a movie atom with a large size value, which triggers a stack-based buffer overflow. | |
| Modificada | Alta (9.3) | 6.3% | — | Apple Quicktime | 7/11/2007 | 16/6/2026 | Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via crafted Sample Table Sample Descriptor (STSD) atoms in a movie file. | |
| Modificada | Alta (9.3) | 7.3% | — | Apple Quicktime | 7/11/2007 | 16/6/2026 | Unspecified vulnerability in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a crafted image description atom in a movie file, related to "memory corruption." | |
| Modificada | Alta (7.6) | 8.1% | — | Apple Quicktime | 7/11/2007 | 16/6/2026 | Stack-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid UncompressedQuickTimeData opcode length in a PICT image. | |
| Modificada | Alta (9.3) | 2.4% | — | Apple Quicktime | 4/10/2007 | 16/6/2026 | Argument injection vulnerability in Apple QuickTime 7.2 for Windows XP SP2 and Vista allows remote attackers to execute arbitrary commands via a URL in the qtnext field in a crafted QTL file. NOTE: this issue may be related to CVE-2006-4965 or CVE-2007-5045. | |
| Modificada | Alta (9.3) | 3.5% | — | Apple QuicktimeMozilla Firefox | 24/9/2007 | 16/6/2026 | Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome"… | |
| Modificada | Alta (9.3) | 6.9% | — | Apple Quicktime | 15/7/2007 | 16/6/2026 | QuickTime for Java in Apple Quicktime before 7.2 does not properly check permissions, which allows remote attackers to disable security controls and execute arbitrary code via crafted Java applets. | |
| Modificada | Alta (9.3) | 6.9% | — | Apple Quicktime | 15/7/2007 | 16/6/2026 | The JDirect support in QuickTime for Java in Apple Quicktime before 7.2 exposes certain dangerous interfaces, which allows remote attackers to execute arbitrary code via crafted Java applets. | |
| Modificada | Alta (9.3) | 6.9% | — | Apple Quicktime | 15/7/2007 | 16/6/2026 | The design of QuickTime for Java in Apple Quicktime before 7.2 allows remote attackers to bypass certain security controls and write to process memory via Java applets, possibly leading to arbitrary code execution. | |
| Modificada | Alta (9.3) | 6.1% | — | Apple Quicktime | 15/7/2007 | 16/6/2026 | Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via a crafted movie file that triggers memory corruption. | |
| Modificada | Media (4.3) | 2.8% | — | Apple Quicktime | 15/7/2007 | 16/6/2026 | QuickTime for Java in Apple Quicktime before 7.2 does not perform sufficient "access control," which allows remote attackers to obtain sensitive information (screen content) via crafted Java applets. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Apple Quicktime | 15/7/2007 | 16/6/2026 | Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to execute arbitrary code via crafted (1) title and (2) author fields in an SMIL file, related to improper calculations for memory allocation. | |
| Modificada | Alta (9.3) | 6.0% | — | Apple Quicktime | 29/5/2007 | 16/6/2026 | Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not properly restrict QTObject subclassing, which allows remote attackers to execute arbitrary code via a web page containing a user-defined class that accesses unsafe functions that can be leveraged to write to arbitrary memory locations. | |
| Modificada | Alta (7.1) | 2.8% | — | Apple Quicktime | 29/5/2007 | 16/6/2026 | Apple QuickTime for Java 7.1.6 on Mac OS X and Windows does not clear potentially sensitive memory before use, which allows remote attackers to read memory from a web browser via unknown vectors related to Java applets. |