Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.96% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 0.99% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (5.5) | 0.45% | — | Google ChromeOpensuse Backports | 25/11/2019 | 17/6/2026 | Insufficient validation of untrusted input in intents in Google Chrome on Android prior to 78.0.3904.70 allowed a local attacker to leak files via a crafted application. | |
| Modificada | Alta (7.8) | 0.77% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Media (4.3) | 0.58% | — | Google ChromeOpensuse Backports | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 78.0.3904.70 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. | |
| Modificada | Media (4.3) | 0.93% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content security policy via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.53% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable. | |
| Modificada | Media (4.3) | 0.92% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeOpensuse Backports SLE | 25/11/2019 | 17/6/2026 | Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.8) | 2.2% | — | PhpmyadminOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 22/11/2019 | 17/6/2026 | An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. | |
| Modificada | Media (6.5) | 1.5% | — | Redhat AnsibleDebian LinuxOpensuse Backports SLEOpensuse Leap | 22/11/2019 | 17/6/2026 | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them. | |
| Modificada | Crítica (9.8) | 2.6% | — | Osgeo GdalOracle Spatial AND GraphDebian LinuxFedoraproject Fedora+2 | 14/10/2019 | 17/6/2026 | GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. | |
| Modificada | Crítica (9.8) | 3.1% | — | Nongnu LibntlmDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+2 | 10/10/2019 | 17/6/2026 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request. | |
| Modificada | Alta (7.8) | 0.51% | — | Redhat Ansible EngineDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 8/10/2019 | 17/6/2026 | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not affect Ansible modules, as those are… | |
| Modificada | Media (6.5) | 2.8% | — | ImagemagickOpensuse BackportsOpensuse LeapCanonical Ubuntu Linux | 23/9/2019 | 17/6/2026 | ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. | |
| Modificada | Media (6.5) | 2.7% | — | Eclipse MosquittoCanonical Ubuntu LinuxOpensuse Backports SLEOpensuse Leap+2 | 19/9/2019 | 17/6/2026 | In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur. | |
| Modificada | Alta (7.5) | 3.2% | — | NIC BirdOpensuse Backports SLEFedoraproject FedoraDebian Linux | 9/9/2019 | 17/6/2026 | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a… | |
| Modificada | Alta (7.5) | 0.95% | — | Imapfilter Project ImapfilterDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 8/9/2019 | 17/6/2026 | IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. | |
| Modificada | Alta (7.8) | 4.1% | — | KDE KconfigDebian LinuxFedoraproject FedoraOpensuse Backports SLE+4 | 7/8/2019 | 17/6/2026 | In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file. | |
| Modificada | Alta (7.8) | 1.3% | — | Schismtracker Schism TrackerOpensuse BackportsOpensuse Leap | 2/8/2019 | 17/6/2026 | An issue was discovered in Schism Tracker through 20190722. There is a heap-based buffer overflow via a large number of song patterns in fmt_mtm_load_song in fmt/mtm.c, a different vulnerability than CVE-2019-14465. | |
| Modificada | Alta (8.8) | 4.0% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately… | |
| Modificada | Alta (8.8) | 3.5% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code… |