Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

58 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)48%⚠ Explotación activaDebian LinuxCanonical Ubuntu LinuxGoogle ChromeSuse Package HUB+629/3/201617/6/2026
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.
ModificadaMedia (4.3)2.2%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox+213/3/201617/6/2026
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
ModificadaMedia (6.5)2.4%—Mozilla FirefoxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse13/3/201617/6/2026
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
ModificadaMedia (4.3)2.0%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox13/3/201617/6/2026
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
ModificadaAlta (8.8)2.3%—Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+213/3/201617/6/2026
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or…
ModificadaAlta (8.8)3.2%—Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+113/3/201617/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
ModificadaAlta (8.8)3.0%—Oracle LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+213/3/201617/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaCrítica (9.8)2.6%—Google ChromeNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+121/2/201617/6/2026
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
Orbitaley — Vulnerabilidades