Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap+121/9/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
ModificadaAlta (8.8)2.9%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaAlta (8.8)2.9%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.6)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaCrítica (9.6)1.5%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaAlta (8.8)1.9%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
ModificadaMedia (4.3)1.2%—Google ChromeOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+121/9/202017/6/2026
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
ModificadaAlta (7.8)0.71%—Nodejs Node.jsOpensuse LeapFedoraproject Fedora18/9/202017/6/2026
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
ModificadaAlta (7.4)5.3%—Nodejs Node.jsOpensuse LeapFedoraproject Fedora18/9/202017/6/2026
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying…
ModificadaAlta (7.8)0.22%—Google AndroidOpensuse Leap17/9/202017/6/2026
In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807
ModificadaMedia (6.7)0.22%—Google AndroidOpensuse Leap17/9/202017/6/2026
In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459
ModificadaMedia (5.5)0.49%—Google AndroidDebian LinuxOpensuse LeapStarwindsoftware Starwind Virtual SAN17/9/202017/6/2026
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171
ModificadaMedia (4.7)0.49%—Perl DBIFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+117/9/202017/6/2026
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
ModificadaAlta (8.8)2.0%—Sylabs SingularityOpensuse Leap16/9/202017/6/2026
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
ModificadaAlta (8.1)2.0%—Sylabs SingularityOpensuse Leap16/9/202017/6/2026
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
ModificadaAlta (7.1)0.61%—Perl Database InterfaceOpensuse LeapDebian LinuxFedoraproject Fedora16/9/202017/6/2026
A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integrity of data.
ModificadaMedia (5.5)0.55%—Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+116/9/202017/6/2026
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
ModificadaAlta (7.8)1.3%💥 PoCLinux KernelDebian LinuxFedoraproject FedoraOpensuse Leap16/9/202017/6/2026
A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.
ModificadaMedia (6.5)3.2%—Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+615/9/202017/6/2026
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or…
ModificadaMedia (4.1)0.31%—Linux KernelDebian LinuxOpensuse Leap13/9/202017/6/2026
The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.
ModificadaAlta (7.5)2.2%—Atftp Project AtftpDebian LinuxOpensuse Leap10/9/202017/6/2026
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
ModificadaAlta (7.5)4.4%—Libproxy Project LibproxyDebian LinuxFedoraproject FedoraOpensuse Leap+19/9/202017/6/2026
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
ModificadaAlta (7)0.27%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux9/9/202017/6/2026
A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.
ModificadaAlta (7)0.65%—Samba Cifs-utilsFedoraproject FedoraOpensuse Leap9/9/202017/6/2026
It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.