Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Improper handling of pending navigation entries in Navigation in Google Chrome on iOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Making URLs clickable and allowing them to be styled in DevTools in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | An object lifetime issue in the developer tools network handler in Google Chrome prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via a crafted HTML page. | |
| Modificada | Media (5.4) | 1.2% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Parsing documents as HTML in Downloads in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to cause Chrome to execute scripts via a local non-HTML page. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | readAsText() can indefinitely read the file picked by the user, rather than only once at the time the file is picked in File API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to access data on the user file system without explicit consent via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | An asynchronous generator may return an incorrect state in V8 in Google Chrome prior to 66.0.3359.117 allowing a remote attacker to potentially exploit object corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Incorrect handling of confusable characters in URL Formatter in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Incorrect handling of asynchronous methods in Fullscreen in Google Chrome on macOS prior to 66.0.3359.117 allowed a remote attacker to enter full screen without showing a warning via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | A JavaScript focused window could overlap the fullscreen notification in Fullscreen in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to obscure the full screen warning via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Insufficient origin checks in Blink in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.1% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Service Workers can intercept any request made by an <embed> or <object> tag in Fetch API in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file. | |
| Modificada | Alta (8.8) | 9.3% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | Type confusion could lead to a heap out-of-bounds write in V8 in Google Chrome prior to 64.0.3282.168 allowing a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| Modificada | Alta (7.4) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | A heap buffer overflow in GPU in Google Chrome prior to 70.0.3538.67 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.8) | 0.62% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 9/1/2019 | 17/6/2026 | An out of bounds read in PDFium in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. | |
| Modificada | Media (6.5) | 0.98% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | Incorrect handling of clicks in the omnibox in Navigation in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.2% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | An improper update of the WebAssembly dispatch table in WebAssembly in Google Chrome prior to 69.0.3497.92 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.1% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files with no user input via a crafted HTML page. | |
| Modificada | Media (6.1) | 1.1% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | The default selected dialog button in CustomHandlers in Google Chrome prior to 69.0.3497.81 allowed a remote attacker who convinced the user to perform certain operations to open external programs via a crafted HTML page. | |
| Modificada | Alta (8.8) | 5.3% | 💥 Exploit | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | An out of bounds read in Swiftshader in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. | |
| Modificada | Alta (7.4) | 1.0% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | Allowing the chrome.debugger API to run on file:// URLs in DevTools in Google Chrome prior to 69.0.3497.81 allowed an attacker who convinced a user to install a malicious extension to access files on the local file system without file access permission via a crafted Chrome Extension. | |
| Modificada | Media (5.3) | 1.1% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | A race condition between permission prompts and navigations in Prompts in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | Unsafe handling of credit card details in Autofill in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 9/1/2019 | 17/6/2026 | Missing bounds check in PDFium in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file. |