Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 317 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-44303
HIGH 7.5 Réseau

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the f…

CVE-2024-44286
HIGH 7.5 Réseau

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard even…

CVE-2024-44250
HIGH 8.2 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of …

CVE-2024-44219
HIGH 7.5 Réseau

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be …

CVE-2024-40858
HIGH 7.1 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user c…

CVE-2024-40849
HIGH 7.5 Réseau

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

CVE-2026-28894
HIGH 7.5 Réseau

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.…

CVE-2026-28891
HIGH 8.1 Local

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be ab…

CVE-2026-28876
HIGH 7.5 Réseau

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 a…

CVE-2026-28875
HIGH 7.5 Réseau

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial…

CVE-2026-28874
HIGH 7.5 Réseau

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.

CVE-2026-28865
HIGH 7.5 Réseau

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ…

CVE-2026-28855
HIGH 7.5 Réseau

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access…

CVE-2026-28842
HIGH 7.5 Réseau

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected …

CVE-2026-28837
HIGH 7.5 Réseau

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVE-2026-28832
HIGH 8.4 Local

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app m…

CVE-2026-28825
HIGH 7.1 Réseau

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A…

CVE-2026-28821
HIGH 8.4 Local

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed i…

CVE-2026-28817
HIGH 8.1 Local

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed pr…

CVE-2026-20701
HIGH 7.5 Réseau

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app …

CVE-2026-20698
HIGH 7.8 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.…

CVE-2026-20687
HIGH 7.1 Local

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ…

CVE-2026-20639
HIGH 7.5 Réseau

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processin…

CVE-2026-20631
HIGH 8.8 Réseau

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.

CVE-2026-20622
HIGH 7.5 Réseau

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to c…

CVE-2026-4371
HIGH 7.4 Réseau 1 apps

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connectio…

CVE-2026-4727
HIGH 7.5 Réseau 1 apps

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4726
HIGH 7.5 Réseau 1 apps

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4718
HIGH 8.1 Réseau 1 apps

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

CVE-2026-4694
HIGH 7.5 Réseau 1 apps

Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, …

CVE-2025-59775
HIGH 7.5

[Apple apache] Multiple issues in Apache

CVE-2025-58098
HIGH 8.3

[Apple apache] Multiple issues in Apache

CVE-2026-4424
HIGH 7.5 Réseau

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sl…

CVE-2026-4224
HIGH 7.5 Réseau 1 apps

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow…

CVE-2026-3644
HIGH 7.5 Réseau 1 apps

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths wer…

CVE-2026-26133
HIGH 7.1 Réseau 13 apps

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2023-43010
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS …

CVE-2026-26134
HIGH 7.8 Local 1 apps

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

CVE-2026-25180
HIGH 5.5 Local 1 apps

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-24294
HIGH 7.8 Local

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

CVE-2026-24293
HIGH 7.8 Local

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVE-2026-24289
HIGH 7.8 Local

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

CVE-2026-24285
HIGH 7.0 Local 1 apps

Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

CVE-2026-26132
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2026-26128
HIGH 7.8

Windows SMB Server Elevation of Privilege Vulnerability

CVE-2026-26111
HIGH 8.0

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2026-25190
HIGH 7.8

Windows GDI Remote Code Execution Vulnerability

CVE-2026-25189
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2026-25188
HIGH 8.8

Windows Telephony Service Elevation of Privilege Vulnerability

CVE-2026-25187
HIGH 7.8

Winlogon Elevation of Privilege Vulnerability