Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.5% | — | Mozilla FirefoxMozilla Firefox ESRCanonical Ubuntu LinuxDebian Linux+5 | 8/1/2020 | 17/6/2026 | Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. | |
| Modificada | Media (6.1) | 2.0% | — | Mozilla FirefoxMozilla Firefox ESRDebian LinuxCanonical Ubuntu Linux+5 | 8/1/2020 | 17/6/2026 | When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. | |
| Modificada | Alta (7.5) | 6.8% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 24/12/2019 | 17/6/2026 | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. | |
| Modificada | Alta (7.5) | 6.8% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 24/12/2019 | 17/6/2026 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). | |
| Modificada | Alta (7.5) | 7.0% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 23/12/2019 | 17/6/2026 | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880. | |
| Modificada | Alta (8.1) | 9.5% | — | Apache Xerces-c++Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+6 | 18/12/2019 | 17/6/2026 | The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a… | |
| Modificada | Alta (8.8) | 2.6% | — | Apple IcloudApple ItunesApple SafariApple Ipados+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, watchOS 6.1, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code… | |
| Modificada | Alta (8.8) | 2.3% | — | Apple IcloudApple ItunesApple SafariApple Ipados+5 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.5% | — | Apple IcloudApple ItunesApple SafariApple Ipados+5 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPadOS 13.2, tvOS 13.2, Safari 13.0.3, iTunes for Windows 12.10.2, iCloud for Windows 11.0, iCloud for Windows 7.15. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 13% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 2.2% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 2.4% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 2.5% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 11% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 2.4% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+6 | 18/12/2019 | 17/6/2026 | Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS 5.3, Safari 12.1.2, iTunes for Windows 12.9.6, iCloud for Windows 7.13, iCloud for Windows 10.6. Processing maliciously crafted web content may lead to arbitrary… | |
| Modificada | Alta (8.8) | 2.3% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+5 | 18/12/2019 | 17/6/2026 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.1% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+5 | 18/12/2019 | 17/6/2026 | A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (8.8) | 2.2% | — | Apple IcloudApple ItunesApple SafariApple Iphone OS+4 | 18/12/2019 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 12.2, tvOS 12.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Analizada | Alta (8.8) | 16% | ⚠ Explotación activa | Apple IcloudApple ItunesApple SafariApple Iphone OS+5 | 18/12/2019 | 17/6/2026 | A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS 5.2, Safari 12.1, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. Processing maliciously crafted web content may lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 6.9% | — | SqliteNetapp Cloud BackupDebian LinuxSuse Package HUB+7 | 18/12/2019 | 17/6/2026 | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. | |
| Modificada | Alta (8.8) | 6.4% | — | Google ChromeDebian LinuxFedoraproject FedoraSuse Package HUB+4 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.2% | — | Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 10/12/2019 | 17/6/2026 | Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. | |
| Modificada | Baja (3.3) | 0.17% | — | Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 10/12/2019 | 17/6/2026 | Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code. | |
| Modificada | Media (4.3) | 1.1% | — | Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 10/12/2019 | 17/6/2026 | Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeDebian LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 10/12/2019 | 17/6/2026 | Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |