Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.6% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.6% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Media (4.3) | 1.0% | — | Powerdns AuthoritativeOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected… | |
| Modificada | Media (5.5) | 2.5% | — | Videolan VLC Media PlayerOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | Double Free in VLC versions <= 3.0.6 leads to a crash. | |
| Modificada | Alta (7.1) | 2.8% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. | |
| Modificada | Media (5.5) | 1.6% | — | Mcpp Project McppOpensuse Backports SLEOpensuse Leap | 26/7/2019 | 17/6/2026 | MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. | |
| Modificada | Crítica (9.8) | 3.7% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 18/7/2019 | 17/6/2026 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. | |
| Modificada | Alta (8.1) | 3.7% | — | Libsdl Simple Directmedia LayerDebian LinuxOpensuse Backports SLEOpensuse Leap+9 | 16/7/2019 | 17/6/2026 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c. | |
| Modificada | Alta (7.8) | 2.1% | — | Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 14/7/2019 | 17/6/2026 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file. | |
| Modificada | Alta (8.8) | 4.5% | — | Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 3/7/2019 | 17/6/2026 | An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image… | |
| Modificada | Alta (8.8) | 4.0% | — | Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 3/7/2019 | 17/6/2026 | An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability. | |
| Modificada | Media (4.3) | 1.0% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 27/6/2019 | 17/6/2026 | Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL. | |
| Modificada | Media (4.3) | 0.77% | — | Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+1 | 27/6/2019 | 17/6/2026 | Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora | 27/6/2019 | 17/6/2026 | Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.3% | — | Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+1 | 27/6/2019 | 17/6/2026 | Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Media (4.3) | 0.96% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+1 | 27/6/2019 | 17/6/2026 | Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.2% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+1 | 27/6/2019 | 17/6/2026 | Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+2 | 27/6/2019 | 17/6/2026 | Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |