Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2003 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Sharing of objects over calls into JavaScript runtime in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (8.8) | 3.3% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/2/2019 | 17/6/2026 | An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.0% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient input validation in WebGL in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of invalid end character position when front rendering in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.2% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.3% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (5.5) | 0.54% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. | |
| Modificada | Alta (8.1) | 1.9% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. | |
| Modificada | Media (6.5) | 0.58% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy. | |
| Modificada | Alta (7.8) | 1.2% | — | Advancemame AdvancecompDebian LinuxFedoraproject FedoraRedhat Enterprise Linux FOR Power Little Endian+2 | 17/2/2019 | 17/6/2026 | An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a… | |
| Modificada | Alta (7.8) | 1.2% | — | Advancemame AdvancecompDebian LinuxFedoraproject FedoraRedhat Enterprise Linux FOR Power Little Endian+2 | 17/2/2019 | 17/6/2026 | An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when… | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Linux KernelDebian LinuxCanonical Ubuntu LinuxF5 Big-ip Access Policy Manager+20 | 15/2/2019 | 17/6/2026 | In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. | |
| Modificada | Alta (8.2) | 0.47% | — | FlatpakDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 12/2/2019 | 17/6/2026 | Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it. | |
| Modificada | Crítica (9.8) | 2.7% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code. |