Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3241▲ 698 respecto a la semana anterior
Críticas / altas1519▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 49% | — | Microsoft Windows Media Player | 13/6/2006 | 16/6/2026 | Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size. | |
| Modificada | Media (5.1) | 3.6% | — | Kaffeine Player | 5/4/2006 | 16/6/2026 | Desbordamiento de búfer en playlistimport.cpp en Kaffein Player 0.4.2 a 0.7.1 permite a atacantes con implicación del usuario ejecutar código de su elección mediante peticiones HTTP largas cuando Kaffeine está "obteniendo listas de reproducción remotas", lo que que dispara un desbordamiento de búfer en la función… | |
| Modificada | Media (5.1) | 3.5% | — | Mplayer | 30/3/2006 | 16/6/2026 | Multiple integer overflows in MPlayer 1.0pre7try2 allow remote attackers to cause a denial of service and trigger heap-based buffer overflows via (1) a certain ASF file handled by asfheader.c that causes the asf_descrambling function to be passed a negative integer after the conversion from a char to an int or (2) an… | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 23/3/2006 | 16/6/2026 | Desbordamiento de buffer en swfformat.dll en múltiples productos y versiones RealNetworks incluyendo RealPlayer 10.x, RealOne Player, Rhapsody 3 y Helix Player permite a atacantes remotos ejecutar código arbitrario a través de un archivo SWF (Flash) manipulado con (1) un valor de tamaño que es menor que el tamaño real… | |
| Modificada | Alta (9.3) | 2.9% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 23/3/2006 | 16/6/2026 | Buffer overflow in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, RealPlayer 8, and RealPlayer Enterprise before 20060322 allows remote attackers to have an unknown impact via a malicious Mimio boardCast (mbc) file. | |
| Modificada | Media (5.1) | 6.8% | — | Macromedia Flash Player | 15/3/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file. | |
| Modificada | Alta (9.3) | 50% | 💥 Exploit | Microsoft Windows Media PlayerMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98+3 | 14/2/2006 | 16/6/2026 | Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but… | |
| Modificada | Alta (7.5) | 4.0% | — | Mplayer | 8/2/2006 | 16/6/2026 | Múltiples desbordamientos de enteros en (1) la función new_demux_packet en demuxer.h y (2) la función demux_asf_read_packet en demux_asf.c en MPlayer 1.0pre7try2 y anteriores permite a atacantes remotos ejecutar código de su elección mediante un fichero ASF con un valor de longitud de paquete grande. NOTA: la… | |
| Modificada | Alta (7.2) | 1.2% | — | Adobe CaptivateAdobe ContributeAdobe DirectorAdobe Dreamweaver+5 | 31/12/2005 | 16/6/2026 | Adobe Macromedia MX 2004 products, Captivate, Contribute 2, Contribute 3, and eLicensing client install the Macromedia Licensing Service with the Users group permitted to configure the service, including the path to executable, which allows local users to execute arbitrary code as Local System. | |
| Modificada | Alta (9.3) | 5.8% | — | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks RealplayerRealnetworks Rhapsody | 31/12/2005 | 16/6/2026 | Heap-based buffer overflow in the embedded player in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, and Helix Player allows remote malicious servers to cause a denial of service (crash) and possibly execute arbitrary code via a chunked Transfer-Encoding HTTP response in which… | |
| Modificada | Alta (9.3) | 20% | — | Adobe Shockwave Player | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in an ActiveX control for the installer for Adobe Macromedia Shockwave Player 10.1.0.11 and earlier allows remote attackers to execute arbitrary code via crafted large values for unspecified parameters. | |
| Analizada | Alta (10) | 14% | — | Vmware ACEVmware GSX ServerVmware PlayerVmware Workstation | 21/12/2005 | 7/7/2026 | Heap-based buffer overflow in the NAT networking components vmnat.exe and vmnet-natd in VMWare Workstation 5.5, GSX Server 3.2, ACE 1.0.1, and Player 1.0 allows remote authenticated attackers, including guests, to execute arbitrary code via crafted (1) EPRT and (2) PORT FTP commands. | |
| Modificada | Alta (7.5) | 1.8% | — | Realnetworks Realplayer | 9/12/2005 | 16/6/2026 | ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows attackers to execute arbitrary code. NOTE: the information regarding this issue is extremely vague and does not… | |
| Modificada | Alta (7.5) | 2.2% | — | Realnetworks Realplayer | 9/12/2005 | 16/6/2026 | ** UNVERIFIABLE, PRERELEASE ** NOTE: this issue describes a problem that can not be independently verified as of 20051208. Unspecified vulnerability in unspecified versions of Real Networks RealPlayer allows remote attackers to execute arbitrary code. NOTE: it is not known whether this issue should be MERGED with… | |
| Modificada | Alta (7.8) | 1.7% | — | Macromedia Breeze Communication ServerAIMacromedia Breeze Live ServerAIMacromedia Flash PlayerAI | 29/11/2005 | 16/6/2026 | Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |
| Modificada | Alta (7.5) | 3.3% | — | Realnetworks Realplayer | 18/11/2005 | 16/6/2026 | Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different. | |
| Modificada | Media (5.1) | 4.5% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Heap-based buffer overflow in DUNZIP32.DLL for RealPlayer 8, 10, and 10.5 and RealOne Player 1 and 2 allows remote attackers to execute arbitrary code via a crafted RealPlayer Skin (RJS) file, a different vulnerability than CVE-2004-1094. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remote attackers to execute arbitrary code via an .rm movie file with a large value in the length field of the first data packet, which leads to a stack-based buffer overflow, a different vulnerability… | |
| Modificada | Alta (7.2) | 3.3% | — | Realnetworks Realone PlayerRealnetworks Realplayer | 18/11/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne Player v1, and RealPlayer 8 before 20060322 might allow local users to gain privileges via a malicious C:\program.exe file. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Macromedia Flash Player | 16/11/2005 | 16/6/2026 | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in a SWF file, which causes an improper… | |
| Modificada | Media (5.1) | 6.8% | — | Macromedia Flash Player | 5/11/2005 | 16/6/2026 | Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer. | |
| Modificada | Media (5) | 40% | — | Microsoft Windows Media Player | 12/10/2005 | 16/6/2026 | QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 2.1% | — | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename. | |
| Modificada | Media (5.1) | 13% | 💥 Exploit | Realnetworks Helix PlayerRealnetworks Realplayer | 27/9/2005 | 16/6/2026 | Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file. |