Vulnérabilités
Vulnérabilités des apps suivies
15 682 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-40778
LOW 3.3
Local
An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sono… |
|
CVE-2024-40777
MEDIUM 5.5
Local
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visio… |
|
CVE-2024-40776
MEDIUM 4.3
Réseau
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.… |
|
CVE-2024-40775
MEDIUM 5.5
Local
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.… |
|
CVE-2024-40774
HIGH 7.1
Local
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma… |
|
CVE-2024-27888
MEDIUM 5.5
Local
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be able to mod… |
|
CVE-2024-27887
MEDIUM 5.5
Local
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data. |
|
CVE-2024-27886
MEDIUM 5.5
Local
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.7. An unprivileged app may be able to log ke… |
|
CVE-2024-27884
MEDIUM 5.5
Local
This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An … |
|
CVE-2024-27883
MEDIUM 4.4
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m… |
|
CVE-2024-27882
MEDIUM 4.4
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m… |
|
CVE-2024-27881
MEDIUM 5.3
Réseau
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Vent… |
|
CVE-2024-27878
MEDIUM 6.7
Local
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit… |
|
CVE-2024-27877
MEDIUM 6.1
Local
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a mali… |
|
CVE-2024-27873
MEDIUM 5.5
Local
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS… |
|
CVE-2024-27872
MEDIUM 5.5
Local
This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be able to access protected user data. |
|
CVE-2024-27871
MEDIUM 5.5
Local
A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app may be able to access … |
|
CVE-2024-27863
MEDIUM 5.5
Local
An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sono… |
|
CVE-2024-27862
LOW 2.4
Physique
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac may cause F… |
|
CVE-2024-27853
MEDIUM 4.4
Local
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks. |
|
CVE-2024-27826
HIGH 7.8
Local
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.6, macOS Sonoma 14.5, macOS Ventura… |
|
CVE-2024-27823
MEDIUM 5.9
Réseau
A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, mac… |
|
CVE-2024-27809
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user… |
|
CVE-2024-23261
HIGH 7.5
Réseau
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker … |
|
CVE-2024-7014
HIGH 8.1
Réseau 1 apps
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older. |
|
CVE-2024-6615
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2024-6614
MEDIUM 4.3
Réseau 1 apps
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6613
MEDIUM 5.5
Local 1 apps
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6612
MEDIUM 5.3
Réseau 1 apps
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CS… |
|
CVE-2024-6611
CRITICAL 9.8
Réseau 1 apps
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. |
|
CVE-2024-6610
MEDIUM 4.3
Réseau 1 apps
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen m… |
|
CVE-2024-6609
HIGH 8.8
Réseau 1 apps
When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird… |
|
CVE-2024-6608
MEDIUM 4.3
Réseau 1 apps
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulner… |
|
CVE-2024-6607
HIGH 8.8
Réseau 1 apps
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `<select>` element ove… |
|
CVE-2024-6606
CRITICAL 9.8
Réseau 1 apps
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunder… |
|
CVE-2024-6604
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-6603
MEDIUM 7.4
Réseau 1 apps
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerabilit… |
|
CVE-2024-6602
CRITICAL 9.8
Réseau 1 apps
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <… |
|
CVE-2024-6601
MEDIUM 4.7
Réseau 1 apps
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < … |
|
CVE-2024-6600
MEDIUM 6.3
Réseau 1 apps
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private s… |
|
CVE-2024-6387
CRITICAL 8.1
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling |
|
CVE-2024-39684
MEDIUM 7.8
Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-38517
MEDIUM 7.8
Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-38112
HIGH 7.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-38105
HIGH 6.5
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38104
HIGH 8.8
Windows Fax Service Remote Code Execution Vulnerability |
|
CVE-2024-38102
HIGH 6.5
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38101
HIGH 6.5
Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability |
|
CVE-2024-38100
HIGH 7.8
Windows File Explorer Elevation of Privilege Vulnerability |
|
CVE-2024-38099
HIGH 5.9
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |