Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
419 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 9.1% | 💥 Exploit | Apple SafariApple Webkit | 22/11/2010 | 16/6/2026 | The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to… | |
| Modificada | Alta (9.3) | 5.8% | — | Apple SafariApple Webkit | 22/11/2010 | 16/6/2026 | Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string. | |
| Modificada | Alta (8.8) | 2.5% | — | Google ChromeWebkitgtkFedoraproject Fedora | 6/11/2010 | 16/6/2026 | Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SVG document,… | |
| Modificada | Crítica (9.8) | 2.3% | — | Google ChromeWebkitgtkFedoraproject Fedora | 6/11/2010 | 16/6/2026 | WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeWebkitgtkFedoraproject Fedora | 6/11/2010 | 16/6/2026 | WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document. | |
| Modificada | Crítica (9.8) | 2.3% | — | Google ChromeWebkitgtkFedoraproject Fedora | 6/11/2010 | 16/6/2026 | Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing. | |
| Modificada | Alta (9.3) | 61% | 💥 Exploit | Apple SafariGoogle AndroidWebkitgtk | 10/9/2010 | 16/6/2026 | WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN… | |
| Modificada | Media (6.8) | 4.4% | — | Apple Iphone OSWebkitgtkCanonical Ubuntu Linux | 9/9/2010 | 16/6/2026 | Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars. | |
| Modificada | Media (6.8) | 4.2% | — | Apple Iphone OSWebkitgtkCanonical Ubuntu Linux | 9/9/2010 | 16/6/2026 | WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus. | |
| Modificada | Media (6.8) | 4.4% | — | Apple Iphone OSWebkitgtkCanonical Ubuntu Linux | 9/9/2010 | 16/6/2026 | Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections. | |
| Modificada | Media (4.3) | 1.6% | — | Google ChromeWebkitgtkApple SafariApple Iphone OS+1 | 7/9/2010 | 16/6/2026 | WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via… | |
| Modificada | Alta (9.3) | 3.3% | — | Google ChromeWebkitgtkApple SafariApple Iphone OS+1 | 7/9/2010 | 16/6/2026 | Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus. | |
| Modificada | Alta (9.3) | 2.0% | — | Google ChromeWebkitgtk | 7/9/2010 | 16/6/2026 | Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (10) | 1.4% | — | Google ChromeWebkitgtk | 24/8/2010 | 16/6/2026 | Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (10) | 3.7% | — | Google ChromeApple SafariApple Iphone OSWebkitgtk+1 | 24/8/2010 | 16/6/2026 | Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of… | |
| Modificada | Media (5) | 1.8% | — | Google ChromeWebkitgtkCanonical Ubuntu Linux | 24/8/2010 | 16/6/2026 | Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors. | |
| Modificada | Alta (10) | 1.8% | — | Google ChromeWebkitgtkCanonical Ubuntu Linux | 24/8/2010 | 16/6/2026 | The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in… | |
| Modificada | Alta (10) | 2.9% | — | Google ChromeWebkitgtkCanonical Ubuntu Linux | 24/8/2010 | 16/6/2026 | Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController. | |
| Modificada | Alta (10) | 2.6% | — | Apple Webkit | 19/8/2010 | 16/6/2026 | loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150. | |
| Modificada | Alta (10) | 2.1% | — | Apple Webkit | 19/8/2010 | 16/6/2026 | page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357. | |
| Modificada | Media (4.3) | 1.1% | — | URS Wolfer Kwebkitpart | 2/8/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple SafariApple Webkit | 30/7/2010 | 16/6/2026 | The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields. | |
| Modificada | Alta (9.3) | 6.7% | — | Apple SafariApple Webkit | 30/7/2010 | 16/6/2026 | Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a (1) font-face or (2) use… | |
| Modificada | Alta (9.3) | 6.0% | — | Apple SafariApple Webkit | 30/7/2010 | 16/6/2026 | WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression. | |
| Modificada | Alta (9.3) | 6.0% | — | Apple SafariApple Webkit | 30/7/2010 | 16/6/2026 | Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a JavaScript array index. |