Vulnérabilités
Vulnérabilités des apps suivies
15 628 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-3087
HIGH 7.5
Réseau 1 apps
If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the… |
|
CVE-2026-6786
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2026-6785
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149. Some of these bugs showed evidence… |
|
CVE-2026-6019
MEDIUM 6.1
Réseau 1 apps
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sen… |
|
CVE-2026-28950
MEDIUM 6.2
Local
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7.16, iOS 18.7.8 and… |
|
CVE-2026-6784
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-6783
MEDIUM 5.3
Réseau 1 apps
Incorrect boundary conditions, integer overflow in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6782
HIGH 7.5
Réseau 1 apps
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6781
HIGH 7.5
Réseau 1 apps
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6780
HIGH 7.5
Réseau 1 apps
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6779
MEDIUM 5.3
Réseau 1 apps
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6778
MEDIUM 5.3
Réseau 1 apps
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6777
MEDIUM 5.3
Réseau 1 apps
Other issue in the Networking: DNS component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6776
HIGH 7.8
Local 1 apps
Incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunde… |
|
CVE-2026-6775
MEDIUM 5.3
Réseau 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6774
MEDIUM 5.4
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6773
HIGH 7.5
Réseau 1 apps
Denial-of-service due to integer overflow in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6772
HIGH 7.5
Réseau 1 apps
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbi… |
|
CVE-2026-6771
CRITICAL 9.8
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6770
MEDIUM 6.5
Réseau 1 apps
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6769
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Debugger component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6768
CRITICAL 9.8
Réseau 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6767
MEDIUM 5.3
Réseau 1 apps
Other issue in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunde… |
|
CVE-2026-6766
HIGH 7.5
Réseau 1 apps
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderb… |
|
CVE-2026-6765
MEDIUM 5.3
Réseau 1 apps
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6764
MEDIUM 6.5
Réseau 1 apps
Incorrect boundary conditions in the DOM: Device Interfaces component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Th… |
|
CVE-2026-6763
MEDIUM 6.5
Réseau 1 apps
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6762
MEDIUM 6.3
Réseau 1 apps
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu… |
|
CVE-2026-6761
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Networking component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6760
CRITICAL 9.8
Réseau 1 apps
Mitigation bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6759
HIGH 7.5
Réseau 1 apps
Use-after-free in the Widget: Cocoa component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6758
HIGH 7.5
Réseau 1 apps
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6757
MEDIUM 6.3
Réseau 1 apps
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140… |
|
CVE-2026-6755
MEDIUM 6.5
Réseau 1 apps
Mitigation bypass in the DOM: postMessage component. This vulnerability was fixed in Firefox 150 and Thunderbird 150. |
|
CVE-2026-6754
HIGH 7.5
Réseau 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Th… |
|
CVE-2026-6753
HIGH 7.3
Réseau 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6752
HIGH 7.3
Réseau 1 apps
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, an… |
|
CVE-2026-6751
HIGH 7.3
Réseau 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-6750
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150… |
|
CVE-2026-6749
HIGH 7.5
Réseau 1 apps
Information disclosure due to uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefo… |
|
CVE-2026-6748
CRITICAL 9.8
Réseau 1 apps
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbir… |
|
CVE-2026-6747
HIGH 7.5
Réseau 1 apps
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10. |
|
CVE-2026-6746
HIGH 7.5
Réseau 1 apps
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thu… |
|
CVE-2026-6358
HIGH 8.8
Réseau 1 apps
Use after free in XR in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML p… |
|
CVE-2026-6319
HIGH 7.5
Réseau 1 apps
Use after free in Payments in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestures… |
|
CVE-2026-6315
HIGH 8.8
Réseau 1 apps
Use after free in Permissions in Google Chrome on Android prior to 147.0.7727.101 allowed a remote attacker who convinced a user to engage in specific UI gestu… |
|
CVE-2026-33829
MEDIUM 4.3
Réseau
Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-33827
HIGH 8.1
Réseau
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code o… |
|
CVE-2026-33826
HIGH 8.0
Réseau adjacent
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. |
|
CVE-2026-33824
CRITICAL 9.8
Réseau
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network. |