Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

1 821 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-11704
CRITICAL 9.8 Réseau 1 apps

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key c…

CVE-2024-11698
CRITICAL 9.8 Réseau 1 apps

A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened durin…

CVE-2024-11693
CRITICAL 9.8 Réseau 1 apps

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating …

CVE-2024-43639
CRITICAL 9.8

Windows KDC Proxy Remote Code Execution Vulnerability

CVE-2024-43625
CRITICAL 8.1

Microsoft Windows VMSwitch Elevation of Privilege Vulnerability

CVE-2024-38408
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-44217
CRITICAL 9.1 Réseau

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may …

CVE-2024-40867
CRITICAL 9.6 Réseau

A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able…

CVE-2024-44206
CRITICAL 9.3 Réseau

An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t…

CVE-2024-9680
CRITICAL 9.8 KEV Réseau 1 apps

An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner…

CVE-2024-43582
CRITICAL 8.1

Remote Desktop Protocol Server Remote Code Execution Vulnerability

CVE-2024-9402
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2024-9401
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptio…

CVE-2024-9392
CRITICAL 9.8 Réseau 1 apps

A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3…

CVE-2024-44148
CRITICAL 10.0 Réseau

This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-44146
CRITICAL 10.0 Réseau

A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.

CVE-2024-8387
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2024-33052
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-33042
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-38160
CRITICAL 9.1

Windows Network Virtualization Remote Code Execution Vulnerability

CVE-2024-38159
CRITICAL 9.1

Windows Network Virtualization Remote Code Execution Vulnerability

CVE-2024-38140
CRITICAL 9.8

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2024-38063
CRITICAL 9.8

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2024-7519
CRITICAL 9.6 Réseau 1 apps

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox esc…

CVE-2024-23350
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-6611
CRITICAL 9.8 Réseau 1 apps

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVE-2024-6606
CRITICAL 9.8 Réseau 1 apps

Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunder…

CVE-2024-6602
CRITICAL 9.8 Réseau 1 apps

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <…

CVE-2024-6387
CRITICAL 8.1

RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling

CVE-2024-38077
CRITICAL 9.8

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

CVE-2024-38076
CRITICAL 9.8

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

CVE-2024-38074
CRITICAL 9.8

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

CVE-2024-38060
CRITICAL 8.8

Windows Imaging Component Remote Code Execution Vulnerability

CVE-2020-8597
CRITICAL 9.8

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-38476
CRITICAL 9.8 Réseau

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend application…

CVE-2024-31320
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-21461
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-30080
CRITICAL 9.8 Réseau

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2019-8457
CRITICAL 9.8

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2023-43556
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-43551
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-43538
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-27280
CRITICAL 9.8 Réseau

A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods …

CVE-2024-4558
CRITICAL 9.6 Réseau

Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2024-23706
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-3863
CRITICAL 9.8 Réseau 1 apps

The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating syst…

CVE-2023-28582
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2024-21408
CRITICAL 5.5

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-21407
CRITICAL 8.1

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2024-23717
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.