Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
–

2404 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)49%—Microsoft Windows Media Player13/6/200616/6/2026
Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.
ModificadaMedia (5.1)3.6%—Kaffeine Player5/4/200616/6/2026
Desbordamiento de búfer en playlistimport.cpp en Kaffein Player 0.4.2 a 0.7.1 permite a atacantes con implicación del usuario ejecutar código de su elección mediante peticiones HTTP largas cuando Kaffeine está "obteniendo listas de reproducción remotas", lo que que dispara un desbordamiento de búfer en la función…
ModificadaMedia (5.1)3.5%—Mplayer30/3/200616/6/2026
Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an…
ModificadaAlta (9.3)17%💥 ExploitRealnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody23/3/200616/6/2026
Desbordamiento de buffer en swfformat.dll en múltiples productos y versiones RealNetworks incluyendo RealPlayer 10.x, RealOne Player, Rhapsody 3 y Helix Player permite a atacantes remotos ejecutar código arbitrario a través de un archivo SWF (Flash) manipulado con (1) un valor de tamaño que es menor que el tamaño real…
ModificadaAlta (9.3)2.9%—Realnetworks Realone PlayerRealnetworks Realplayer23/3/200616/6/2026
Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file.
ModificadaMedia (5.1)6.8%—Macromedia Flash Player15/3/200616/6/2026
Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.
ModificadaAlta (9.3)50%💥 ExploitMicrosoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+314/2/200616/6/2026
Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but…
ModificadaAlta (7.5)4.0%—Mplayer8/2/200616/6/2026
Múltiples desbordamientos de enteros en (1) la función new_demux_packet en demuxer.h y (2) la función demux_asf_read_packet en demux_asf.c en MPlayer 1.0pre7try2 y anteriores permite a atacantes remotos ejecutar código de su elección mediante un fichero ASF con un valor de longitud de paquete grande. NOTA: la…
ModificadaAlta (7.2)1.2%—Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+531/12/200516/6/2026
Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System.
ModificadaAlta (9.3)5.8%—Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody31/12/200516/6/2026
Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which…
ModificadaAlta (9.3)20%—Adobe Shockwave Player31/12/200516/6/2026
Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters.
AnalizadaAlta (10)14%—Vmware ACEVmware GSX ServerVmware PlayerVmware Workstation21/12/20057/7/2026
Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands.
ModificadaAlta (7.5)1.8%—Realnetworks Realplayer9/12/200516/6/2026
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not…
ModificadaAlta (7.5)2.2%—Realnetworks Realplayer9/12/200516/6/2026
** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows remote attackers to execute arbitrary code. NOTE: it is not known whether this issue should be MERGED with…
ModificadaAlta (7.8)1.7%—Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI29/11/200516/6/2026
Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133).
ModificadaAlta (7.5)3.3%—Realnetworks Realplayer18/11/200516/6/2026
Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different.
ModificadaMedia (5.1)4.5%—Realnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094.
ModificadaMedia (5.1)13%💥 ExploitRealnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability…
ModificadaAlta (7.2)3.3%—Realnetworks Realone PlayerRealnetworks Realplayer18/11/200516/6/2026
Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file.
ModificadaAlta (7.5)10%💥 ExploitMacromedia Flash Player16/11/200516/6/2026
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper…
ModificadaMedia (5.1)6.8%—Macromedia Flash Player5/11/200516/6/2026
Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.
ModificadaMedia (5)40%—Microsoft Windows Media Player12/10/200516/6/2026
QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.
ModificadaAlta (7.5)5.5%💥 ExploitVirtools WEB Player4/10/200516/6/2026
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.
ModificadaMedia (5)2.1%—Virtools WEB Player4/10/200516/6/2026
Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.
ModificadaMedia (5.1)13%💥 ExploitRealnetworks Helix PlayerRealnetworks Realplayer27/9/200516/6/2026
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.