Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
522 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Apple SafariApple Iphone OSApple TvosApple Icloud+2 | 20/7/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit Page Loading" component. It allows remote attackers… | |
| Modificada | Alta (8.8) | 7.0% | 💥 Exploit | Apple SafariApple Iphone OSApple TvosApple Icloud+2 | 20/7/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute… | |
| Modificada | Media (5.3) | 1.4% | — | Apple SafariApple Iphone OSApple TvosApple Webkit | 20/7/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct a timing side-channel attack to bypass the Same Origin Policy and obtain sensitive… | |
| Modificada | Alta (7.5) | 1.7% | — | Webkitgtk | 10/3/2017 | 17/6/2026 | Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies. | |
| Modificada | Alta (7.5) | 3.1% | — | Webkit | 7/3/2017 | 17/6/2026 | The regex code in Webkit 2.4.11 allows remote attackers to cause a denial of service (memory consumption) as demonstrated in a large number of ($ (open parenthesis and dollar) followed by {-2,16} and a large number of +) (plus close parenthesis). | |
| Modificada | Alta (8.8) | 6.1% | 💥 Exploit | Apple TvosApple SafariApple Iphone OSWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via… | |
| Modificada | Alta (8.8) | 6.1% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via… | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosApple Watchos+1 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information… | |
| Modificada | Alta (7.8) | 4.2% | 💥 Exploit | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+1 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of… | |
| Modificada | Alta (8.8) | 1.9% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Alta (8.8) | 2.1% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Alta (8.8) | 1.9% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Media (6.5) | 1.8% | — | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | |
| Modificada | Media (5.5) | 1.3% | — | Webkit | 3/2/2017 | 17/6/2026 | JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file. | |
| Modificada | Media (6.5) | 2.2% | — | Apple WebkitWebkitgtk+ | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted web site. | |
| Modificada | Alta (7.5) | 4.3% | — | Apple Webkit | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors. | |
| Modificada | Media (5.4) | 1.5% | — | Apple SafariApple Webkit | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site. | |
| Modificada | Alta (8.8) | 2.6% | — | Apple Webkit | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4622, CVE-2016-4623, and CVE-2016-4624. | |
| Modificada | Alta (8.8) | 1.9% | — | Apple Webkit | 22/7/2016 | 17/6/2026 | WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | |
| Modificada | Media (6.5) | 2.1% | — | Apple Webkit | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via a crafted web site. | |
| Modificada | Media (6.1) | 1.9% | — | Apple Webkit | 22/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari. | |
| Modificada | Baja (3.1) | 1.8% | — | Apple WebkitWebkitgtk+ | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document. | |
| Modificada | Alta (8.8) | 2.6% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | |
| Modificada | Media (6.5) | 2.2% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site. |