Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 8.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 6.2% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352,… | |
| Modificada | Alta (10) | 10% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359. | |
| Modificada | Alta (7.5) | 1.3% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux ServerRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 41.0.2272.76 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Google ChromeCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+2 | 9/3/2015 | 17/6/2026 | The getHiddenProperty function in bindings/core/v8/V8EventListenerList.h in Blink, as used in Google Chrome before 41.0.2272.76, has a name conflict with the AudioContext class, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that adds an… | |
| Modificada | Media (5) | 0.95% | — | Canonical Ubuntu LinuxGoogle ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+2 | 9/3/2015 | 17/6/2026 | net/http/proxy_client_socket.cc in Google Chrome before 41.0.2272.76 does not properly handle a 407 (aka Proxy Authentication Required) HTTP status code accompanied by a Set-Cookie header, which allows remote proxy servers to conduct cookie-injection attacks via a crafted response. | |
| Modificada | Alta (7.5) | 1.4% | — | Canonical Ubuntu LinuxGoogle ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+2 | 9/3/2015 | 17/6/2026 | The RenderCounter::updateCounter function in core/rendering/RenderCounter.cpp in Blink, as used in Google Chrome before 41.0.2272.76, does not force a relayout operation and consequently does not initialize memory for a data structure, which allows remote attackers to cause a denial of service (application crash) or… | |
| Modificada | Media (6.8) | 1.9% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+2 | 9/3/2015 | 17/6/2026 | Use-after-free vulnerability in the GIFImageReader::parseData function in platform/image-decoders/gif/GIFImageReader.cpp in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted frame size in a GIF image. | |
| Modificada | Alta (7.5) | 1.4% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted allocation of a large amount of memory… | |
| Modificada | Alta (7.5) | 1.4% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | Multiple use-after-free vulnerabilities in the DOM implementation in Blink, as used in Google Chrome before 41.0.2272.76, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger movement of a SCRIPT element to different documents, related to (1) the… | |
| Modificada | Alta (7.5) | 2.1% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | The V8LazyEventListener::prepareListenerObject function in bindings/core/v8/V8LazyEventListener.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, does not properly compile listeners, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via… | |
| Modificada | Alta (7.5) | 1.4% | — | Google ChromeCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+2 | 9/3/2015 | 17/6/2026 | Use-after-free vulnerability in the V8Window::namedPropertyGetterCustom function in bindings/core/v8/custom/V8WindowCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that… | |
| Modificada | Alta (7.5) | 1.7% | — | Canonical Ubuntu LinuxRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+2 | 9/3/2015 | 17/6/2026 | The filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an out-of-bounds write operation. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+2 | 9/3/2015 | 17/6/2026 | Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a reset action with a large… | |
| Modificada | Media (5) | 1.6% | — | Canonical Ubuntu LinuxOpensuseRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+4 | 22/1/2015 | 17/6/2026 | Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.6% | — | ChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 22/1/2015 | 17/6/2026 | The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Media (5) | 1.6% | — | ChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+3 | 22/1/2015 | 17/6/2026 | The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an incorrect data type for a certain length value, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted X11 data. | |
| Modificada | Media (4.3) | 2.5% | — | Google ChromeChromiumRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server Supplementary+3 | 22/1/2015 | 17/6/2026 | Google Chrome before 40.0.2214.91, when the Harmony proxy in Google V8 is enabled, allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code with Proxy.create and console.log calls, related to HTTP responses that lack an "X-Content-Type-Options: nosniff" header. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+5 | 22/1/2015 | 17/6/2026 | The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a zero-length quantifier. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+5 | 22/1/2015 | 17/6/2026 | The Regular Expressions package in International Components for Unicode (ICU) 52 before SVN revision 292944, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via vectors related to a look-behind expression. | |
| Modificada | Baja (3.4) | 100% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Modificada | Alta (7.5) | 1.4% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+1 | 8/10/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in Google Chrome before 38.0.2125.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | |
| Modificada | Media (5) | 1.3% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+1 | 8/10/2014 | 17/6/2026 | The wrap function in bindings/core/v8/custom/V8EventCustom.cpp in the V8 bindings in Blink, as used in Google Chrome before 38.0.2125.101, has an erroneous fallback outcome for wrapper-selection failures, which allows remote attackers to cause a denial of service via vectors that trigger stopping a worker process that… | |
| Modificada | Media (5) | 1.3% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+1 | 8/10/2014 | 17/6/2026 | The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 value as an index instead of a no-visible-page error code, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |
| Modificada | Media (5) | 0.96% | — | Google ChromeRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+1 | 8/10/2014 | 17/6/2026 | The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, does not properly provide substitute data for pages blocked by the XSS auditor, which allows remote attackers to obtain sensitive information via a crafted web site. |