Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Google ChromeOpensuse Backports SLEOpensuse Leap | 23/5/2019 | 17/6/2026 | Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. | |
| Modificada | Media (6.5) | 1.1% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 23/5/2019 | 17/6/2026 | Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Media (6.5) | 0.99% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | Insufficient policy enforcement in extensions in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to initiate the extensions installation user interface via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.2% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | Integer overflow in PDFium in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially perform out of bounds memory access via a crafted PDF file. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | Inappropriate optimization in V8 in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | An integer overflow leading to an incorrect capacity of a buffer in JavaScript in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. | |
| Modificada | Alta (8.8) | 9.3% | 💥 Exploit | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. | |
| Modificada | Alta (8.8) | 9.1% | 💥 Exploit | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeOpensuse BackportsOpensuse Leap | 23/5/2019 | 17/6/2026 | Use-after-garbage-collection in Blink in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.0% | — | Libsdl Sdl2 ImageLibsdl Simple Directmedia LayerFedoraproject FedoraCanonical Ubuntu Linux+3 | 20/5/2019 | 17/6/2026 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c. | |
| Modificada | Alta (7.4) | 2.0% | — | Heimdal Project HeimdalFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 15/5/2019 | 17/6/2026 | In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. | |
| Modificada | Alta (8.8) | 2.1% | — | Sylabs SingularityFedoraproject FedoraOpensuse BackportsOpensuse Leap | 14/5/2019 | 17/6/2026 | An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can… | |
| Modificada | Alta (8.1) | 2.4% | — | KDE KauthOpensuse LeapOpensuse BackportsFedoraproject Fedora | 7/5/2019 | 17/6/2026 | KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run… | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in… | |
| Modificada | Alta (8.8) | 2.9% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in… | |
| Modificada | Media (6.5) | 2.2% | — | GraphicsmagickFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+2 | 23/4/2019 | 17/6/2026 | coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (8.1) | 2.2% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+5 | 17/4/2019 | 17/6/2026 | The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both… | |
| Modificada | Alta (8.1) | 2.2% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+5 | 17/4/2019 | 17/6/2026 | The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and… | |
| Modificada | Baja (3.7) | 3.5% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+5 | 17/4/2019 | 17/6/2026 | The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access… | |
| Modificada | Media (5.9) | 3.9% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+4 | 17/4/2019 | 17/6/2026 | The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE… | |
| Modificada | Alta (8.8) | 3.8% | — | GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. | |
| Modificada | Alta (8.1) | 2.0% | — | GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 8/4/2019 | 17/6/2026 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap. | |
| Modificada | Media (4.3) | 0.77% | — | Roundcube WebmailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap | 7/4/2019 | 17/6/2026 | In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the… |