Vulnérabilités
Vulnérabilités des apps suivies
1 821 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-2760
CRITICAL 10.0
Réseau 1 apps
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire… |
|
CVE-2026-2759
CRITICAL 9.8
Réseau 1 apps
Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderb… |
|
CVE-2026-2758
CRITICAL 9.8
Réseau 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunde… |
|
CVE-2026-2757
CRITICAL 9.8
Réseau 1 apps
Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunder… |
|
CVE-2026-20677
CRITICAL 9.0
Réseau
A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS S… |
|
CVE-2026-0892
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2026-0884
CRITICAL 9.8
Réseau 1 apps
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0881
CRITICAL 10.0
Réseau 1 apps
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0879
CRITICAL 9.8
Réseau 1 apps
Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140… |
|
CVE-2025-43526
CRITICAL 9.8
Réseau
This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content o… |
|
CVE-2025-43428
CRITICAL 9.8
Réseau
A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in t… |
|
CVE-2025-62557
CRITICAL 8.4
Local 1 apps
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-62554
CRITICAL 8.4
Local 1 apps
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-14330
CRITICAL 9.8
Réseau 1 apps
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14… |
|
CVE-2025-14326
CRITICAL 9.8
Réseau 1 apps
Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146. |
|
CVE-2025-14324
CRITICAL 9.8
Réseau 1 apps
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146… |
|
CVE-2025-14321
CRITICAL 9.8
Réseau 1 apps
Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6. |
|
CVE-2025-48638
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-48624
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-48623
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-47372
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-47319
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-60724
CRITICAL 9.8
Réseau 1 apps
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. |
|
CVE-2025-60716
CRITICAL 7.0
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-48593
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-59234
CRITICAL 7.8
Local 1 apps
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-59227
CRITICAL 7.8
Local 1 apps
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-11721
CRITICAL 9.8
Réseau 1 apps
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could h… |
|
CVE-2025-11719
CRITICAL 9.8
Réseau 1 apps
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.… |
|
CVE-2025-11710
CRITICAL 9.8
Réseau 1 apps
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised proce… |
|
CVE-2025-11709
CRITICAL 9.8
Réseau 1 apps
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability … |
|
CVE-2025-11708
CRITICAL 9.8
Réseau 1 apps
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4. |
|
CVE-2025-59287
CRITICAL 9.8
KEV
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability |
|
CVE-2025-49708
CRITICAL 9.9
Microsoft Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-43362
CRITICAL 9.8
Réseau
The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor keystrokes w… |
|
CVE-2025-43359
CRITICAL 9.8
Réseau
A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS So… |
|
CVE-2025-43347
CRITICAL 9.8
Réseau
This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An inp… |
|
CVE-2025-43343
CRITICAL 9.8
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26… |
|
CVE-2025-43342
CRITICAL 9.8
Réseau
A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS … |
|
CVE-2025-31255
CRITICAL 9.8
Réseau
An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS … |
|
CVE-2025-53799
CRITICAL 5.5
Local 1 apps
Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally. |
|
CVE-2025-55236
CRITICAL 7.3
Graphics Kernel Remote Code Execution Vulnerability |
|
CVE-2025-55228
CRITICAL 7.8
Windows Graphics Component Remote Code Execution Vulnerability |
|
CVE-2025-55226
CRITICAL 6.7
Graphics Kernel Remote Code Execution Vulnerability |
|
CVE-2025-55224
CRITICAL 7.8
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2025-54918
CRITICAL 8.8
Windows NTLM Elevation of Privilege Vulnerability |
|
CVE-2025-53800
CRITICAL 7.8
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2025-39682
CRITICAL 9.8
Réseau
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process … |
|
CVE-2025-27034
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2025-21483
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |