Vulnérabilités
Vulnérabilités des apps suivies
40 CVE touchent une app ou un OS suivi (Critique, Windows). 22 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 40
- Activement exploitées
- 22
- Fenêtre de publication
- 2010-06-30 → 2025-10-14
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2022-21907
CRITICAL 9.8
HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2020-1472
CRITICAL 10.0
KEV
Netlogon Elevation of Privilege Vulnerability |
|
CVE-2020-0796
CRITICAL 10.0
KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows S… |
|
CVE-2014-4650
CRITICAL 9.8
1 app
The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attacke… |
|
CVE-2020-0610
CRITICAL 9.8
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
|
CVE-2020-0609
CRITICAL 9.8
Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability |
|
CVE-2019-1152
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1151
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1150
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1149
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1145
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-1144
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2019-11708
CRITICAL 10.0
KEV
1 app
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op… |
|
CVE-2019-11705
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in … |
|
CVE-2019-11704
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting… |
|
CVE-2019-11703
CRITICAL 9.8
1 app
A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a pot… |
|
CVE-2019-9792
CRITICAL 9.8
1 app
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then b… |
|
CVE-2019-9791
CRITICAL 9.8
1 app
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just… |
|
CVE-2018-8544
CRITICAL 7.5
Windows VBScript Engine Remote Code Execution Vulnerability |
|
CVE-2018-5159
CRITICAL 9.8
1 app
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr… |
|
CVE-2017-5465
CRITICAL 9.1
1 app
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i… |
|
CVE-2017-5447
CRITICAL 9.1
1 app
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to … |
|
CVE-2017-5404
CRITICAL 9.8
1 app
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results i… |
|
CVE-2017-5375
CRITICAL 9.8
1 app
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <… |
|
CVE-2016-9899
CRITICAL 9.8
1 app
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5… |
|
CVE-2017-9417
CRITICAL 8.8
Broadcom BCM43xx Remote Code Execution Vulnerability |
|
CVE-2017-8682
CRITICAL 8.4
Win32k Graphics Remote Code Execution Vulnerability |
|
CVE-2017-8464
CRITICAL 7.5
KEV
LNK Remote Code Execution Vulnerability |
|
CVE-2017-0283
CRITICAL 8.8
Windows Uniscribe Remote Code Execution Vulnerability |
|
CVE-2017-0148
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0146
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0143
CRITICAL 8.1
KEV
Windows SMB Remote Code Execution Vulnerability |
|
CVE-2017-0084
CRITICAL 8.8
Windows Uniscribe Remote Code Execution Vulnerability |
|
CVE-2016-7274
CRITICAL 7.5
Windows Uniscribe Remote Code Execution Vulnerability |
|
CVE-2016-3301
CRITICAL 8.8
Microsoft Graphics Remote Code Execution Vulnerability |
|
CVE-2014-1511
CRITICAL 9.8
1 app
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocke… |
|
CVE-2014-1510
CRITICAL 9.8
1 app
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attac… |
|
CVE-2010-3765
CRITICAL 9.8
KEV
1 app
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja… |
|
CVE-2010-1205
CRITICAL 9.8
1 app
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbi… |