Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

424 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.6%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
ModificadaAlta (8.8)3.6%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
ModificadaMedia (4.3)1.0%—Powerdns AuthoritativeOpensuse BackportsOpensuse Leap30/7/201917/6/2026
A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected…
ModificadaMedia (5.5)2.5%—Videolan VLC Media PlayerOpensuse BackportsOpensuse Leap30/7/201917/6/2026
Double Free in VLC versions <= 3.0.6 leads to a crash.
ModificadaAlta (7.1)2.8%—Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap30/7/201917/6/2026
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
ModificadaMedia (5.5)1.6%—Mcpp Project McppOpensuse Backports SLEOpensuse Leap26/7/201917/6/2026
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
ModificadaCrítica (9.8)3.7%—Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+118/7/201917/6/2026
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
ModificadaAlta (8.1)3.7%—Libsdl Simple Directmedia LayerDebian LinuxOpensuse Backports SLEOpensuse Leap+916/7/201917/6/2026
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
ModificadaAlta (7.8)2.1%—Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+114/7/201917/6/2026
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
ModificadaAlta (8.8)4.5%—Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+13/7/201917/6/2026
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image…
ModificadaAlta (8.8)4.0%—Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+13/7/201917/6/2026
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
ModificadaMedia (4.3)1.0%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+127/6/201917/6/2026
Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
ModificadaMedia (4.3)1.3%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
ModificadaMedia (4.3)0.77%—Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+127/6/201917/6/2026
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
ModificadaMedia (6.5)1.5%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Resource size information leakage in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Heap buffer overflow in ANGLE in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.6%—Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora27/6/201917/6/2026
Object lifecycle issue in SwiftShader in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+127/6/201917/6/2026
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaMedia (4.3)0.96%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports+127/6/201917/6/2026
Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.
ModificadaMedia (6.5)1.2%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.4%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Insufficient policy enforcement in CORS in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaAlta (8.8)1.3%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Integer overflow in download manager in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaAlta (8.8)1.4%—Google ChromeOpensuse BackportsOpensuse LeapDebian Linux+127/6/201917/6/2026
Object lifecycle issue in ServiceWorker in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse BackportsOpensuse LeapFedoraproject Fedora+227/6/201917/6/2026
Integer overflow in SQLite via WebSQL in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.