Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 4.0% | — | Google Picasa | 17/11/2015 | 17/6/2026 | Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 4.0% | — | Google Picasa | 9/11/2015 | 17/6/2026 | Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow. | |
| Modificada | Media (4.3) | 1.6% | — | WP Picasa Image Project WP Picasa Image | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in picasa_upload.php in the WP-Picasa-Image plugin 1.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the post_id parameter. | |
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Stack-based buffer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 might allow remote attackers to execute arbitrary code via a crafted RAW file, as demonstrated using a KDC file with a certain size. | |
| Modificada | Alta (7.5) | 1.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to trigger memory corruption via a crafted TIFF tag, as demonstrated using a KDC file with a DSLR-A100 model and certain sequences of tags. | |
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Integer overflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a long TIFF tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a long TIFF StripByteCounts tag. | |
| Modificada | Alta (7.5) | 2.3% | — | Google Picasa | 9/1/2014 | 16/6/2026 | Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPEG tag value and a small size. | |
| Modificada | Alta (9.3) | 4.3% | — | Google Picasa | 28/7/2011 | 16/6/2026 | Google Picasa before 3.6 Build 105.67 does not properly handle invalid properties in JPEG images, which allows remote attackers to execute arbitrary code via a crafted image file. | |
| Modificada | Media (6.9) | 0.32% | — | Google Picasa | 28/3/2011 | 16/6/2026 | Untrusted search path vulnerability in the Locate on Disk feature in Google Picasa before 3.8 allows local users to gain privileges via a Trojan horse executable file in the current working directory. | |
| Modificada | Media (6.8) | 9.4% | — | Masselink COM Picasa2gallery | 28/6/2010 | 16/6/2026 | Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 16% | — | Roberto Aloi COM Joomlapicasa2 | 8/4/2010 | 16/6/2026 | Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 0.53% | — | Google Picasa | 12/9/2007 | 16/6/2026 | Google Picasa allows remote attackers to read image files stored by Picasa via unspecified vectors involving a picasa:// URI. NOTE: this information is based upon a vague pre-advisory. | |
| Modificada | Media (6.8) | 0.44% | — | Google Picasa | 11/9/2007 | 16/6/2026 | Multiple cross-application scripting (XAS) vulnerabilities in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory. | |
| Modificada | Alta (7.5) | 0.47% | — | Google Picasa | 11/9/2007 | 16/6/2026 | Multiple buffer overflows in Google Picasa have unspecified attack vectors and impact. NOTE: this information is based upon a vague pre-advisory. |