Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2003 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.86%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
ModificadaMedia (6.5)1.2%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
ModificadaMedia (6.5)1.2%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
ModificadaMedia (6.5)1.2%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
ModificadaMedia (5.3)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
ModificadaMedia (6.5)2.5%—Google ChromeIcu-project International Components FOR UnicodeDebian LinuxCanonical Ubuntu Linux+328/8/201817/6/2026
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaMedia (6.5)1.3%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationDebian Linux+128/8/201817/6/2026
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
ModificadaMedia (4.3)1.6%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
ModificadaMedia (5.3)1.5%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
ModificadaMedia (6.5)1.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationDebian Linux+128/8/201817/6/2026
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.
ModificadaMedia (6.5)1.7%—Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationDebian Linux+128/8/201817/6/2026
Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.9%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationDebian Linux+228/8/201817/6/2026
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
ModificadaAlta (8.8)1.6%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.5%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
ModificadaAlta (8.8)2.4%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+728/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptRedhat Enterprise Linux Desktop+527/8/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+727/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
ModificadaAlta (7.8)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+427/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
ModificadaCrítica (9.8)8.9%—Apache MOD PerlDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+326/8/201816/6/2026
mod_perl 2.0 through 2.0.10 allows attackers to execute arbitrary Perl code by placing it in a user-owned .htaccess file, because (contrary to the documentation) there is no configuration option that permits Perl code for the administrator's control of HTTP request processing without also permitting unprivileged users…
ModificadaCrítica (9.8)4.8%—X.org Libx11Canonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+324/8/201817/6/2026
An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.
Orbitaley — Vulnerabilidades