Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
3145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (5.5) | 0.54% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent. | |
| Modificada | Alta (8.8) | 1.4% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect pointer management in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Failure to check error conditions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Insufficient checks of pointer validity in WebRTC in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.6) | 1.5% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 1.8% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | An incorrect object type assumption in SVG in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.7% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. | |
| Modificada | Alta (8.1) | 1.9% | — | Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 19/2/2019 | 17/6/2026 | Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. | |
| Modificada | Media (6.5) | 0.58% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 19/2/2019 | 17/6/2026 | Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy. | |
| Modificada | Alta (7.8) | 1.2% | — | Advancemame AdvancecompDebian LinuxFedoraproject FedoraRedhat Enterprise Linux FOR Power Little Endian+2 | 17/2/2019 | 17/6/2026 | An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a… | |
| Modificada | Alta (7.8) | 1.2% | — | Advancemame AdvancecompDebian LinuxFedoraproject FedoraRedhat Enterprise Linux FOR Power Little Endian+2 | 17/2/2019 | 17/6/2026 | An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when… | |
| Modificada | Alta (8.1) | 17% | 💥 Exploit | Linux KernelDebian LinuxCanonical Ubuntu LinuxF5 Big-ip Access Policy Manager+20 | 15/2/2019 | 17/6/2026 | In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free. | |
| Modificada | Alta (8.2) | 0.47% | — | FlatpakDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 12/2/2019 | 17/6/2026 | Flatpak before 1.0.7, and 1.1.x and 1.2.x before 1.2.3, exposes /proc in the apply_extra script sandbox, which allows attackers to modify a host-side executable file. | |
| Modificada | Alta (8.6) | 98% | 💥 Exploit | DockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+15 | 11/2/2019 | 17/6/2026 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,… | |
| Modificada | Crítica (9.8) | 2.3% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it. | |
| Modificada | Crítica (9.8) | 2.7% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code. | |
| Modificada | Media (5.5) | 1.3% | — | Elfutils Project ElfutilsDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+7 | 9/2/2019 | 17/6/2026 | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes. | |
| Modificada | Media (5.5) | 1.0% | — | Elfutils Project ElfutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 9/2/2019 | 17/6/2026 | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash). | |
| Modificada | Alta (7.8) | 1.8% | — | SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+5 | 6/2/2019 | 17/6/2026 | SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. | |
| Modificada | Media (5.9) | 2.2% | — | Mozilla FirefoxCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+8 | 5/2/2019 | 17/6/2026 | When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured,… | |
| Modificada | Crítica (10) | 4.4% | — | Mozilla FirefoxMozilla ThunderbirdCanonical Ubuntu LinuxDebian Linux+6 | 5/2/2019 | 17/6/2026 | An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not… |