Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

15 629 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2025-6075
MEDIUM 5.5 Local 1 apps

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-43313
MEDIUM 5.5 Local

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be abl…

CVE-2025-43282
MEDIUM 5.5 Local

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS So…

CVE-2025-43281
HIGH 7.8 Local

The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

CVE-2025-43280
MEDIUM 4.7 Réseau

The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail i…

CVE-2025-59234
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-59227
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-11721
CRITICAL 9.8 Réseau 1 apps

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could h…

CVE-2025-11719
CRITICAL 9.8 Réseau 1 apps

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.…

CVE-2025-11716
MEDIUM 6.5 Réseau 1 apps

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11715
HIGH 8.8 Réseau 1 apps

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruptio…

CVE-2025-11714
HIGH 8.8 Réseau 1 apps

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence…

CVE-2025-11713
HIGH 8.1 Réseau 1 apps

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the app…

CVE-2025-11712
MEDIUM 6.1 Réseau 1 apps

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5 Réseau 1 apps

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-11710
CRITICAL 9.8 Réseau 1 apps

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised proce…

CVE-2025-11709
CRITICAL 9.8 Réseau 1 apps

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

CVE-2025-11708
CRITICAL 9.8 Réseau 1 apps

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVE-2025-59502
MEDIUM 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-59295
HIGH 8.8

Windows URL Parsing Remote Code Execution Vulnerability

CVE-2025-59294
HIGH 2.1

Windows Taskbar Live Preview Information Disclosure Vulnerability

CVE-2025-59290
HIGH 7.8

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59289
HIGH 7.0

Windows Bluetooth Service Elevation of Privilege Vulnerability

CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-59284
HIGH 3.3

Windows NTLM Spoofing Vulnerability

CVE-2025-59282
HIGH 7.0

Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability

CVE-2025-59280
HIGH 3.1

Windows SMB Client Tampering Vulnerability

CVE-2025-59278
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59277
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59275
HIGH 7.8

Windows Authentication Elevation of Privilege Vulnerability

CVE-2025-59261
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-59260
HIGH 5.5

Microsoft Failover Cluster Virtual Driver Information Disclosure Vulnerability

CVE-2025-59259
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-59258
HIGH 6.2

Windows Active Directory Federation Services (ADFS) Information Disclosure Vulnerability

CVE-2025-59257
HIGH 6.5

Windows Local Session Manager (LSM) Denial of Service Vulnerability

CVE-2025-59255
HIGH 7.8

Windows DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59254
HIGH 7.8

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2025-59253
HIGH 5.5

Windows Search Service Denial of Service Vulnerability

CVE-2025-59244
HIGH 6.5

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-59242
HIGH 7.8

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2025-59241
HIGH 7.8

Windows Health and Optimized Experiences Elevation of Privilege Vulnerability

CVE-2025-59230
HIGH 7.8 KEV

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

CVE-2025-59214
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-59211
HIGH 5.5

Windows Push Notification Information Disclosure Vulnerability

CVE-2025-59210
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2025-59209
HIGH 5.5

Windows Push Notification Information Disclosure Vulnerability

CVE-2025-59208
HIGH 7.1

Windows MapUrlToZone Information Disclosure Vulnerability

CVE-2025-59207
HIGH 7.8

Windows Kernel Elevation of Privilege Vulnerability

CVE-2025-59206
HIGH 7.4

Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability

CVE-2025-59205
HIGH 7.0

Windows Graphics Component Elevation of Privilege Vulnerability