Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
926 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.42% | — | Apple Itunes | 20/5/2016 | 17/6/2026 | Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Media (6.8) | 2.4% | — | Apple ItunesApple Iphone OSApple MAC OS X | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and… | |
| Modificada | Media (6.8) | 2.5% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Media (6.8) | 2.3% | — | Apple ItunesApple Safari | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and… | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Media (6.8) | 2.4% | — | Apple ItunesApple Safari | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple Safari before 9.0.1 and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-3 and… | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Media (6.8) | 2.8% | — | Apple ItunesApple SafariApple Iphone OS | 23/10/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9.1, Safari before 9.0.1, and iTunes before 12.3.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-10-21-1,… | |
| Modificada | Alta (7.5) | 3.6% | — | Apple ItunesApple Iphone OSApple MAC OS X | 23/10/2015 | 17/6/2026 | CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-6992. | |
| Modificada | Alta (7.5) | 3.7% | — | Apple ItunesApple Iphone OSApple MAC OS X | 23/10/2015 | 17/6/2026 | CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6975 and CVE-2015-7017. | |
| Modificada | Alta (7.5) | 3.7% | — | Apple ItunesApple Iphone OSApple MAC OS X | 23/10/2015 | 17/6/2026 | CoreText in Apple iOS before 9.1, OS X before 10.11.1, and iTunes before 12.3.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6992 and CVE-2015-7017. | |
| Modificada | Media (4.3) | 1.2% | — | Apple Itunes | 18/9/2015 | 17/6/2026 | The Software Update component in Apple iTunes before 12.3 does not properly handle redirection, which allows man-in-the-middle attackers to discover encrypted SMB credentials via unspecified vectors. | |
| Modificada | Alta (7.5) | 4.3% | — | Apple MAC OS XApple ItunesApple Iphone OSApple Watchos | 18/9/2015 | 17/6/2026 | CoreText in Apple iOS before 9 and iTunes before 12.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file. | |
| Modificada | Media (6.8) | 2.5% | — | Apple Iphone OSApple ItunesApple Safari | 18/9/2015 | 17/6/2026 | WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and… | |
| Modificada | Media (6.8) | 2.8% | — | Apple SafariApple Iphone OSApple Itunes | 18/9/2015 | 17/6/2026 | WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and… | |
| Modificada | Media (6.8) | 2.5% | — | Apple SafariApple ItunesApple Iphone OS | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | |
| Modificada | Media (6.8) | 2.5% | — | Apple ItunesApple SafariApple Iphone OS | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple Iphone OSApple Safari | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | |
| Modificada | Media (6.8) | 2.7% | — | Apple SafariApple ItunesApple Iphone OS | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. | |
| Modificada | Media (6.8) | 2.5% | — | Apple Iphone OSApple SafariApple Itunes | 18/9/2015 | 17/6/2026 | WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and… | |
| Modificada | Media (6.8) | 2.3% | — | Apple SafariApple Itunes | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iTunes before 12.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-3. | |
| Modificada | Media (6.8) | 2.7% | — | Apple Iphone OSApple SafariApple Itunes | 18/9/2015 | 17/6/2026 | WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and… | |
| Modificada | Media (6.8) | 2.7% | — | Apple ItunesApple Iphone OSApple Safari | 18/9/2015 | 17/6/2026 | WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3. |