Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.45% | — | Gomlab GOM Player | 15/12/2025 | 17/6/2026 | GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction. | |
| Analizada | Media (6.7) | 0.48% | — | Gomlab GOM Player | 15/12/2025 | 17/6/2026 | GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability. | |
| Modificada | Alta (7.8) | 8.2% | — | Gomlab GOM Player | 21/2/2017 | 17/6/2026 | GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file. | |
| Modificada | Media (4.3) | 1.5% | — | Gomlab GOM Player | 12/8/2014 | 17/6/2026 | Gretech GOM Player 2.2.51.5149 and earlier allows remote attackers to cause a denial of service (launch outage) via a crafted image file. | |
| Modificada | Media (4.3) | 2.1% | — | Gomlab GOM Player | 24/1/2014 | 17/6/2026 | Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file. | |
| Modificada | Media (4.3) | 2.1% | — | Gomlab GOM Player | 9/9/2013 | 16/6/2026 | Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. | |
| Modificada | Alta (10) | 1.8% | — | Gomlab GOM Player | 9/9/2013 | 16/6/2026 | Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors. | |
| Modificada | Alta (9.3) | 6.8% | — | Gomlab GOM Player | 15/9/2012 | 16/6/2026 | Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: this issue exists because of a CVE-2007-0707 regression. | |
| Modificada | Alta (9.3) | 6.8% | — | Gomlab GOM Player | 1/5/2009 | 16/6/2026 | Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in an SRT file. | |
| Modificada | Alta (7.5) | 72% | — | GOM Player | 1/11/2007 | 16/6/2026 | Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Player (GOM Player) 2.1.6.3499 allows remote attackers to execute arbitrary code via a long argument to the OpenUrl method. | |
| Modificada | Media (6.8) | 3.9% | — | GOM Player | 4/2/2007 | 16/6/2026 | Stack-based buffer overflow in GOM Player 2.0.12.3375 allows user-assisted remote attackers to execute arbitrary code via a .ASX file with a long URI in the "ref href" tag. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. |