Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Google Chrome OS16/3/201417/6/2026
The AsyncPixelTransfersCompletedQuery::End function in gpu/command_buffer/service/query_manager.cc in Google Chrome, as used in Google Chrome OS before 33.0.1750.152, does not check whether a certain position is within the bounds of a shared-memory segment, which allows remote attackers to cause a denial of service…
ModificadaAlta (10)2.1%—Google Chrome OS16/3/201417/6/2026
The boot implementation in Google Chrome OS before 33.0.1750.152 does not properly consider file persistence, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)0.83%—Google Chrome OS16/3/201417/6/2026
Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.
ModificadaAlta (7.5)0.64%—Google Chrome OS16/3/201417/6/2026
crosh in Google Chrome OS before 33.0.1750.152 allows attackers to inject commands via unspecified vectors.
ModificadaMedia (4.3)1.4%—Google ChromeGoogle Chrome OS19/6/201316/6/2026
The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's…
ModificadaMedia (5)0.69%—Google Chrome OS16/4/201316/6/2026
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2834.
ModificadaMedia (5)0.90%—Google Chrome OS16/4/201316/6/2026
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechanism via a crafted web site, a different vulnerability than CVE-2013-2835.
ModificadaAlta (10)1.6%—Google Chrome OS16/4/201316/6/2026
Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships involving Elements and DrawElements.
ModificadaMedia (5)0.92%—Google Chrome OS16/4/201316/6/2026
The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote attackers to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)0.83%—Google Chrome OS10/4/201316/6/2026
Google Chrome OS before 26.0.1410.57 relies on a Pango pango-utils.c read_config implementation that loads the contents of the .pangorc file in the user's home directory, and the file referenced by the PANGO_RC_FILE environment variable, which allows attackers to bypass intended access restrictions via crafted…
ModificadaAlta (10)0.73%—Google Chrome OS18/3/201316/6/2026
The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an "overflow."
ModificadaAlta (7.5)1.1%—Google ChromeGoogle Chrome OS4/12/201216/6/2026
Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU process crash) or possibly have unspecified other impact via unknown vectors.
ModificadaAlta (10)4.6%—Google Chrome OS22/8/201216/6/2026
Mesa, as used in Google Chrome before 21.0.1183.0 on the Acer AC700, Cr-48, and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, allows remote attackers to execute arbitrary code via unspecified vectors that trigger an "array overflow."
ModificadaAlta (10)0.70%—Google Chrome OS24/7/201216/6/2026
Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors.
ModificadaAlta (10)0.69%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Chromebox 3+27/6/201216/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.68%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook29/2/201216/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.68%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook12/1/201216/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.67%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook9/12/201116/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.88%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook24/11/201116/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.89%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook12/9/201116/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.125 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.91%—Google Chrome OSAcer Ac700 ChromebookGoogle Cr-48 ChromebookSamsung Series 5 Chromebook12/9/201116/6/2026
Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
ModificadaAlta (10)0.67%—Google Chrome OS24/5/201116/6/2026
Unspecified vulnerability in the dbugs package in Google Chrome OS before R12 0.12.433.38 Beta has unknown impact and attack vectors.
ModificadaMedia (4.4)0.16%—Google Chrome OS24/5/201116/6/2026
Google Chrome OS before R12 0.12.433.38 Beta, when Guest mode is enabled, does not prevent changes on the about:flags page, which has unspecified impact and local attack vectors.
ModificadaAlta (7.2)0.17%—Google Chrome OS24/5/201116/6/2026
Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing commands in it.
ModificadaAlta (10)0.68%—Google Chrome OS8/3/201116/6/2026
Unspecified vulnerability in the Scratchpad application in Google Chrome OS before R10 0.10.156.46 Beta has unknown impact and attack vectors.
Orbitaley — Vulnerabilidades