Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
83 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Debian LinuxRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+3 | 23/7/2015 | 17/6/2026 | Use-after-free vulnerability in the GPU process implementation in Google Chrome before 44.0.2403.89 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging the continued availability of a GPUChannelHost data structure during Blink shutdown, related to… | |
| Modificada | Media (6.8) | 1.9% | — | OpensuseGoogle ChromeDebian LinuxRedhat Enterprise Linux Desktop Supplementary+3 | 23/7/2015 | 17/6/2026 | PDFium, as used in Google Chrome before 44.0.2403.89, does not properly handle certain out-of-memory conditions, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted PDF document that triggers a large memory allocation. | |
| Modificada | Media (6.8) | 2.7% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 23/7/2015 | 17/6/2026 | The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names with initial x- substrings, which allows remote attackers to cause a denial of service (read of uninitialized memory) or possibly have… | |
| Modificada | Alta (7.5) | 1.7% | — | Canonical Ubuntu LinuxGoogle ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+3 | 1/5/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.135 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Google ChromeDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop Supplementary+3 | 1/5/2015 | 17/6/2026 | Use-after-free vulnerability in the MutationObserver::disconnect function in core/dom/MutationObserver.cpp in the DOM implementation in Blink, as used in Google Chrome before 42.0.2311.135, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an attempt to… | |
| Modificada | Media (5) | 9.4% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Supplementary+5 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (10) | 37% | 💥 Exploit | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Media (5) | 4.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism via unspecified vectors, a different vulnerability than… | |
| Modificada | Alta (10) | 7.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-0358. | |
| Modificada | Alta (10) | 7.0% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 10% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Workstation ExtensionAdobe Flash Player+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0351, and CVE-2015-3039. | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 7.8% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039. | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0352,… | |
| Modificada | Alta (10) | 8.2% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039. | |
| Modificada | Alta (10) | 8.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 6.2% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352,… | |
| Modificada | Alta (10) | 10% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359. | |
| Modificada | Alta (7.5) | 1.3% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux ServerRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Google ChromeCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+2 | 9/3/2015 | 17/6/2026 | The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an… |