Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
1671 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | Apple SafariApple MAC OS XApple MAC OS X Server | 26/10/2005 | 16/6/2026 | Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Apple Safari | 21/9/2005 | 16/6/2026 | Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL. | |
| Modificada | Alta (7.5) | 4.8% | — | Apple SafariApple MAC OS X | 19/8/2005 | 16/6/2026 | Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. | |
| Modificada | Media (5.1) | 4.3% | — | Apple SafariApple MAC OS X | 19/8/2005 | 16/6/2026 | Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file. | |
| Modificada | Baja (2.6) | 1.1% | — | Apple SafariApple MAC OS X | 19/8/2005 | 16/6/2026 | Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Apple Safari | 17/8/2005 | 16/6/2026 | Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within the function body. | |
| Modificada | Baja (2.6) | 1.9% | — | Apple Safari | 13/7/2005 | 16/6/2026 | Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability." | |
| Modificada | Baja (2.6) | 2.2% | — | Apple Safari | 3/5/2005 | 16/6/2026 | Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference. | |
| Modificada | Media (5) | 1.8% | — | Apple SafariHmdt ShiiraOmnigroup Omniweb | 2/5/2005 | 16/6/2026 | AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript component, as demonstrated using automatically mounted disk images and file:// URLs. | |
| Modificada | Media (4.3) | 1.3% | — | Apple Safari | 2/5/2005 | 16/6/2026 | Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks. | |
| Modificada | Media (5) | 1.7% | — | Apple Safari | 2/5/2005 | 16/6/2026 | The International Domain Name (IDN) support in Safari 1.2.5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. | |
| Modificada | Alta (7.5) | 2.4% | — | Apple Safari | 10/1/2005 | 16/6/2026 | Safari 1.x allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability, a different vulnerability than… | |
| Modificada | Media (5) | 1.6% | — | Apple Safari | 10/1/2005 | 16/6/2026 | Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays. | |
| Modificada | Alta (7.5) | 2.3% | — | Apple Safari | 10/1/2005 | 16/6/2026 | Safari 1.x to 1.2.4, and possibly other versions, allows inactive windows to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows, aka the "Dialog Box Spoofing Vulnerability," a different vulnerability than CVE-2004-1314. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Apple SafariAI | 23/11/2004 | 16/6/2026 | The Javascript engine in Safari 1.2 and earlier allows remote attackers to cause a denial of service (segmentation fault) by creating a new Array object with a large size value, then writing into that array. | |
| Modificada | Media (5) | 4.4% | 💥 Exploit | Apple Safari | 1/11/2004 | 16/6/2026 | Apple Safari 1.0 through 1.2.3 allows remote attackers to spoof the URL displayed in the status bar via TABLE tags. | |
| Modificada | Alta (7.5) | 1.3% | — | Apple Safari | 27/7/2004 | 16/6/2026 | Safari 1.2.2 no previene adecuadamente que un marco de un dominio inyecte contenido en un marco que pertenece a otro dominio, lo que facilita la suplantación de sitios web y otros ataques. Vulnerabilidad también conocida como "de inyección de marco". | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Apple Safari | 15/4/2004 | 16/6/2026 | Apple Safari permite a atacantes remotos saltarse las restriciones de cookies pretendidas en una aplicación web mediante secuencias de atravesamiento de directorios "%2e%2e" (punto punto codificado) en una URL, lo que hace que Safari envíe la cookie fuera de los subconjuntos de URL especificados, por ejemplo a una… | |
| Modificada | Media (5) | 1.4% | — | Apple SafariApple MAC OS XApple MAC OS X Server | 15/12/2003 | 16/6/2026 | Apple Safari 1.0 a 1.1 en Mac OS X 10.3.1 y Mac OS X 10.2.8 permite a atacantes remotos robar 'cookies' de usuarios de otro dominio mediante un enlace con un carácter nulo codificado-hex (%00) seguido del dominio objetivo. | |
| Modificada | Alta (7.5) | 2.1% | — | Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+2 | 16/6/2003 | 16/6/2026 | Konqueror Embedded y KDE 2.2.2 y anteriores no validan el campo Common Name (CN) en certificados X.509, lo que permitiría que atacantes remotos falsifiquen certificados mediante un ataque "man-in-the-middle". | |
| Modificada | Media (5) | 0.77% | — | Apple SafariKDE Konqueror Embedded | 9/6/2003 | 16/6/2026 | Safari 1.0 Beta 2 (v73) y anteriores no validan el campo Common Name (CN) para Certificados X.509, lo que permitiría a atacantes remotos falsificar certificados. |