Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.0% | — | Apple SafariApple Iphone OSApple WatchosApple Icloud+7 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. watchOS before 4.3 is affected. The issue involves the fetch API in the "WebKit" component. It allows remote attackers… | |
| Modificada | Alta (8.8) | 2.0% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves the "WebKit" component. It allows… | |
| Modificada | Media (6.5) | 2.1% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+4 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. The issue involves a JavaScriptCore function in the… | |
| Modificada | Alta (8.8) | 1.9% | — | Apple SafariApple Iphone OSApple TvosApple Icloud+3 | 3/4/2018 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary… | |
| Modificada | Media (5.3) | 1.1% | — | Webkitgtk+ | 1/11/2017 | 17/6/2026 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secondary process to cause a denial of service (release assertion) of the UI process. This vulnerability does not affect Apple products. | |
| Modificada | Crítica (9.8) | 1.2% | — | Webkitgtk+ | 1/11/2017 | 17/6/2026 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect Apple products. | |
| Modificada | Alta (7.5) | 1.7% | — | Webkitgtk | 10/3/2017 | 17/6/2026 | Late TLS certificate verification in WebKitGTK+ prior to 2.6.6 allows remote attackers to view a secure HTTP request, including, for example, secure cookies. | |
| Modificada | Alta (8.8) | 6.1% | 💥 Exploit | Apple TvosApple SafariApple Iphone OSWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via… | |
| Modificada | Alta (8.8) | 6.1% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via… | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | |
| Modificada | Media (6.5) | 7.0% | 💥 Exploit | Apple Iphone OSApple SafariApple TvosApple Watchos+1 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information… | |
| Modificada | Alta (7.8) | 4.2% | 💥 Exploit | Apple Iphone OSApple MAC OS XApple TvosApple Watchos+1 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of… | |
| Modificada | Alta (8.8) | 1.9% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Alta (8.8) | 2.1% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Alta (8.8) | 1.9% | — | Apple Iphone OSApple SafariApple IcloudApple Itunes+2 | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. iCloud before 6.1.1 is affected. iTunes before 12.5.5 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause… | |
| Modificada | Media (6.5) | 1.8% | — | Apple Iphone OSApple SafariApple TvosWebkitgtk+ | 20/2/2017 | 17/6/2026 | An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site. | |
| Modificada | Media (6.5) | 2.2% | — | Apple WebkitWebkitgtk+ | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted web site. | |
| Modificada | Baja (3.1) | 1.8% | — | Apple WebkitWebkitgtk+ | 22/7/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document. | |
| Modificada | Alta (8.8) | 2.6% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | |
| Modificada | Media (6.5) | 2.2% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted web site. | |
| Modificada | Alta (8.8) | 2.9% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856. | |
| Modificada | Alta (8.8) | 2.6% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857. | |
| Modificada | Alta (8.8) | 2.6% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 20/5/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857. | |
| Modificada | Alta (8.8) | 3.1% | — | Apple SafariApple Iphone OSApple TvosWebkitgtk+ | 24/3/2016 | 17/6/2026 | WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | |
| Modificada | Alta (8.8) | 4.5% | — | Apple SafariApple Iphone OSApple TvosApple Watchos+1 | 1/2/2016 | 17/6/2026 | WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724. |