Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.42% | — | XENDebian LinuxFedoraproject FedoraOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the… | |
| Modificada | Media (5.5) | 0.43% | — | XENFedoraproject FedoraOpensuse LeapDebian Linux | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023… | |
| Modificada | Alta (7) | 0.29% | — | XENFedoraproject FedoraOpensuse LeapDebian Linux | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or… | |
| Modificada | Media (5.5) | 0.42% | — | XENFedoraproject FedoraOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar to forgetting to… | |
| Modificada | Media (5.5) | 0.51% | — | XENFedoraproject FedoraDebian LinuxOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the… | |
| Modificada | Alta (7.8) | 0.37% | — | XENFedoraproject FedoraDebian LinuxOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect… | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.3) | 1.4% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Alta (7.8) | 0.36% | — | Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary. | |
| Modificada | Crítica (9.6) | 1.8% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. | |
| Modificada | Media (4.3) | 1.2% | — | Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction. | |
| Modificada | Media (6.3) | 1.3% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.7% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.5% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.6% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.3% | — | Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+1 | 21/9/2020 | 17/6/2026 | Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.8% | — | Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux | 21/9/2020 | 17/6/2026 | Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | |
| Modificada | Alta (8.8) | 3.3% | — | Google ChromeDebian LinuxFedoraproject FedoraOpensuse Leap | 21/9/2020 | 17/6/2026 | Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |