Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 48% | ⚠ Explotación activa | Debian LinuxCanonical Ubuntu LinuxGoogle ChromeSuse Package HUB+6 | 29/3/2016 | 17/6/2026 | The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code. | |
| Modificada | Media (4.3) | 2.2% | — | Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox+2 | 13/3/2016 | 17/6/2026 | Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array. | |
| Modificada | Media (6.5) | 2.4% | — | Mozilla FirefoxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse | 13/3/2016 | 17/6/2026 | Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader. | |
| Modificada | Media (4.3) | 2.0% | — | Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox | 13/3/2016 | 17/6/2026 | Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element. | |
| Modificada | Alta (8.8) | 2.3% | — | Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+2 | 13/3/2016 | 17/6/2026 | The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or… | |
| Modificada | Alta (8.8) | 3.2% | — | Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+1 | 13/3/2016 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors. | |
| Modificada | Alta (8.8) | 3.0% | — | Oracle LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+2 | 13/3/2016 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Crítica (9.8) | 2.6% | — | Google ChromeNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+1 | 21/2/2016 | 17/6/2026 | Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors. |