Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Google Chrome OS | 16/3/2014 | 17/6/2026 | The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service… | |
| Modificada | Alta (10) | 2.1% | — | Google Chrome OS | 16/3/2014 | 17/6/2026 | The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.83% | — | Google Chrome OS | 16/3/2014 | 17/6/2026 | Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors. | |
| Modificada | Alta (7.5) | 0.64% | — | Google Chrome OS | 16/3/2014 | 17/6/2026 | crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Google ChromeGoogle Chrome OS | 19/6/2013 | 16/6/2026 | The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's… | |
| Modificada | Media (5) | 0.69% | — | Google Chrome OS | 16/4/2013 | 16/6/2026 | Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834. | |
| Modificada | Media (5) | 0.90% | — | Google Chrome OS | 16/4/2013 | 16/6/2026 | Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2835. | |
| Modificada | Alta (10) | 1.6% | — | Google Chrome OS | 16/4/2013 | 16/6/2026 | Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships involving Elements and DrawElements. | |
| Modificada | Media (5) | 0.92% | — | Google Chrome OS | 16/4/2013 | 16/6/2026 | The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.83% | — | Google Chrome OS | 10/4/2013 | 16/6/2026 | Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted… | |
| Modificada | Alta (10) | 0.73% | — | Google Chrome OS | 18/3/2013 | 16/6/2026 | The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an "overflow." | |
| Modificada | Alta (7.5) | 1.1% | — | Google ChromeGoogle Chrome OS | 4/12/2012 | 16/6/2026 | Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (10) | 4.6% | — | Google Chrome OS | 22/8/2012 | 16/6/2026 | Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow." | |
| Modificada | Alta (10) | 0.70% | — | Google Chrome OS | 24/7/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.69% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Chromebox 3+2 | 7/6/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.68% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 29/2/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.68% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/1/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.67% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 9/12/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.88% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 24/11/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.89% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.91% | — | Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook | 12/9/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors. | |
| Modificada | Alta (10) | 0.67% | — | Google Chrome OS | 24/5/2011 | 16/6/2026 | Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors. | |
| Modificada | Media (4.4) | 0.16% | — | Google Chrome OS | 24/5/2011 | 16/6/2026 | Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors. | |
| Modificada | Alta (7.2) | 0.17% | — | Google Chrome OS | 24/5/2011 | 16/6/2026 | Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it. | |
| Modificada | Alta (10) | 0.68% | — | Google Chrome OS | 8/3/2011 | 16/6/2026 | Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 Beta has unknown impact and attack vectors. |