Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.46% | — | IBM Trusteer Android SDK FOR MobileIBM Trusteer IOS SDK FOR Mobile | 17/2/2024 | 17/6/2026 | An undisclosed issue in Trusteer iOS SDK for mobile versions prior to 5.7 and Trusteer Android SDK for mobile versions prior to 5.7 may allow uploading of files. IBM X-Force ID: 238535. | |
| Modificada | Media (5.9) | 0.66% | — | Matrix ElementMatrix-android-sdk2 | 13/9/2021 | 17/6/2026 | A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by… | |
| Modificada | Alta (7.5) | 2.1% | — | Google Android Debug BridgeGoogle Android SDK Platform ToolsOpensuse | 14/5/2014 | 17/6/2026 | Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allows ADB servers to execute arbitrary code via a negative length value, which bypasses a signed comparison and triggers a stack-based buffer overflow. | |
| Modificada | Media (4.3) | 1.2% | — | Google Android SDK | 8/7/2011 | 16/6/2026 | dexdump in Android SDK before 2.3 does not properly perform structural verification, which allows user-assisted remote attackers to cause a denial of service (dexdump crash) and possibly execute arbitrary code via a malformed APK or dex file that calls a method using more arguments than the number of register that… | |
| Modificada | Alta (7.2) | 0.36% | — | Android SDK | 17/2/2009 | 16/6/2026 | Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines. | |
| Modificada | Alta (7.2) | 0.32% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions. | |
| Modificada | Alta (7.2) | 0.30% | — | Openhandsetalliance Android SDK | 17/2/2009 | 16/6/2026 | The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to… | |
| Modificada | Media (6.8) | 4.6% | — | Google Android SDK | 6/3/2008 | 16/6/2026 | Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actual height and width. | |
| Modificada | Alta (7.5) | 4.9% | — | Google Android SDK | 6/3/2008 | 16/6/2026 | Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field. |