Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
–

1671 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.1%—Apple SafariApple MAC OS XApple MAC OS X Server26/10/200516/6/2026
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
ModificadaMedia (5)3.0%💥 ExploitApple Safari21/9/200516/6/2026
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
ModificadaAlta (7.5)4.8%—Apple SafariApple MAC OS X19/8/200516/6/2026
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands.
ModificadaMedia (5.1)4.3%—Apple SafariApple MAC OS X19/8/200516/6/2026
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
ModificadaBaja (2.6)1.1%—Apple SafariApple MAC OS X19/8/200516/6/2026
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
ModificadaMedia (5)3.1%💥 ExploitApple Safari17/8/200516/6/2026
Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body.
ModificadaBaja (2.6)1.9%—Apple Safari13/7/200516/6/2026
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."
ModificadaBaja (2.6)2.2%—Apple Safari3/5/200516/6/2026
Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.
ModificadaMedia (5)1.8%—Apple SafariHmdt ShiiraOmnigroup Omniweb2/5/200516/6/2026
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs.
ModificadaMedia (4.3)1.3%—Apple Safari2/5/200516/6/2026
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
ModificadaMedia (5)1.7%—Apple Safari2/5/200516/6/2026
The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
ModificadaAlta (7.5)2.4%—Apple Safari10/1/200516/6/2026
Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than…
ModificadaMedia (5)1.6%—Apple Safari10/1/200516/6/2026
Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
ModificadaAlta (7.5)2.3%—Apple Safari10/1/200516/6/2026
Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314.
ModificadaMedia (5)7.0%💥 ExploitApple SafariAI23/11/200416/6/2026
The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array.
ModificadaMedia (5)4.4%💥 ExploitApple Safari1/11/200416/6/2026
Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags.
ModificadaAlta (7.5)1.3%—Apple Safari27/7/200416/6/2026
Safari 1.2.2 no previene adecuadamente que un marco de un dominio inyecte contenido en un marco que pertenece a otro dominio, lo que facilita la suplantación de sitios web y otros ataques. Vulnerabilidad también conocida como "de inyección de marco".
ModificadaAlta (7.5)5.4%💥 ExploitApple Safari15/4/200416/6/2026
Apple Safari permite a atacantes remotos saltarse las restriciones de cookies pretendidas en una aplicación web mediante secuencias de atravesamiento de directorios "%2e%2e" (punto punto codificado) en una URL, lo que hace que Safari envíe la cookie fuera de los subconjuntos de URL especificados, por ejemplo a una…
ModificadaMedia (5)1.4%—Apple SafariApple MAC OS XApple MAC OS X Server15/12/200316/6/2026
Apple Safari 1.0 a 1.1 en Mac OS X 10.3.1 y Mac OS X 10.2.8 permite a atacantes remotos robar 'cookies' de usuarios de otro dominio mediante un enlace con un carácter nulo codificado-hex (%00) seguido del dominio objetivo.
ModificadaAlta (7.5)2.1%—Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+216/6/200316/6/2026
Konqueror Embedded y KDE 2.2.2 y anteriores no validan el campo Common Name (CN) en certificados X.509, lo que permitiría que atacantes remotos falsifiquen certificados mediante un ataque "man-in-the-middle".
ModificadaMedia (5)0.77%—Apple SafariKDE Konqueror Embedded9/6/200316/6/2026
Safari 1.0 Beta 2 (v73) y anteriores no validan el campo Common Name (CN) para Certificados X.509, lo que permitiría a atacantes remotos falsificar certificados.