Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.8% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 24/12/2019 | 17/6/2026 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). | |
| Modificada | Crítica (9.1) | 2.8% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c. | |
| Modificada | Crítica (9.8) | 2.5% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. | |
| Modificada | Crítica (9.8) | 2.7% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/12/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. | |
| Modificada | Alta (7.5) | 7.0% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 23/12/2019 | 17/6/2026 | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880. | |
| Modificada | Alta (7.8) | 1.6% | — | Lout Project LoutOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 20/12/2019 | 17/6/2026 | Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. | |
| Modificada | Alta (7.8) | 1.5% | — | Lout Project LoutOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 20/12/2019 | 17/6/2026 | Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. | |
| Modificada | Alta (7.5) | 6.9% | — | SqliteNetapp Cloud BackupDebian LinuxSuse Package HUB+7 | 18/12/2019 | 17/6/2026 | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. | |
| Analizada | Media (5.9) | 1.4% | — | Excon Project ExconOpensuse Backports SLEOpensuse LeapDebian Linux | 16/12/2019 | 28/7/2026 | In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be… | |
| Modificada | Alta (8.8) | 6.4% | 💥 PoC | Google ChromeDebian LinuxFedoraproject FedoraSuse Package HUB+4 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxSuse Package HUBOpensuse Backports SLE+4 | 10/12/2019 | 17/6/2026 | Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.9% | — | Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 10/12/2019 | 17/6/2026 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+5 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.76% | — | Shadowsocks-libevOpensuse Backports SLEOpensuse Leap | 3/12/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network packets sent to ss-manager can cause an arbitrary binary to run, resulting in code execution and privilege escalation. An attacker can send network packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.6% | — | Shadowsocks-libevOpensuse BackportsOpensuse Leap | 3/12/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the UDPRelay functionality of Shadowsocks-libev 3.3.2. When utilizing a Stream Cipher and a local_address, arbitrary UDP packets can cause a FATAL error code path and exit. An attacker can send arbitrary UDP packets to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.7% | — | Redhat AnsibleOpensuse Backports SLEOpensuse LeapRedhat Openstack | 26/11/2019 | 17/6/2026 | ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeFedoraproject FedoraOpensuse BackportsRedhat Enterprise Linux Desktop+2 | 25/11/2019 | 17/6/2026 | Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.2% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.88% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (4.3) | 1.0% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.93% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.85% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (6.1) | 0.83% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL. | |
| Modificada | Media (6.5) | 1.1% | — | Google ChromeOpensuse Backports | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (5.3) | 1.2% | — | Google ChromeOpensuse Backports | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in JavaScript in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |