Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.4)0.98%—GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+1029/7/202017/6/2026
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and…
ModificadaMedia (6.4)1.4%—GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+1029/7/202017/6/2026
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects…
ModificadaCrítica (9.8)5.2%—Artifex GhostscriptCanonical Ubuntu LinuxOpensuse Leap28/7/202017/6/2026
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit…
ModificadaBaja (3.5)1.5%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+127/7/202017/6/2026
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the…
ModificadaCrítica (9.8)2.6%—Claws-mailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap23/7/202017/6/2026
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
ModificadaMedia (4.3)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to install a PWA to spoof the contents of the Omnibox (URL bar) via a crafted PWA.
ModificadaMedia (6.1)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.2%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+122/7/202017/6/2026
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
ModificadaMedia (4.3)1.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaMedia (4.3)1.5%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.9%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.6)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaMedia (6.5)1.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaAlta (8.8)2.7%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)10%💥 ExploitGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
ModificadaAlta (8.8)2.6%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap+122/7/202017/6/2026
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.8%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (4.3)4.8%💥 PoCGoogle ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+122/7/202017/6/2026
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.