Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 297 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-45655
MEDIUM 5.3 Physique

Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.

CVE-2026-45634
MEDIUM 5.5 Local

Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.

CVE-2026-45608
MEDIUM 6.8 Local

Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally.

CVE-2026-45606
MEDIUM 5.5 Local

Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.

CVE-2026-45604
MEDIUM 5.5 Local

Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.

CVE-2026-45595
MEDIUM 5.4 Réseau

Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.

CVE-2026-45594
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat…

CVE-2026-44814
MEDIUM 5.5 Local

Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVE-2026-44805
MEDIUM 5.5 Local

Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally.

CVE-2026-42973
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42972
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-42971
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42970
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42969
MEDIUM 5.5 Local

Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.

CVE-2026-42968
MEDIUM 5.5 Local

Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally.

CVE-2026-42915
MEDIUM 5.5 Local

Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally.

CVE-2026-42914
MEDIUM 5.3 Réseau

Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-42907
MEDIUM 6.5 Réseau

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network.

CVE-2026-42906
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.

CVE-2026-42903
MEDIUM 6.5 Réseau

Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network.

CVE-2026-48112
MEDIUM 6.5 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A …

CVE-2026-48111
MEDIUM 4.3 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedenc…

CVE-2026-48104
MEDIUM 4.2 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused b…

CVE-2026-48103
MEDIUM 4.3 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) …

CVE-2026-48101
MEDIUM 6.5 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI cap…

CVE-2026-48092
MEDIUM 4.3 Réseau 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overf…

CVE-2026-28581
MEDIUM 4.0 Local

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lea…

CVE-2026-28578
MEDIUM 5.5 Local

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to loca…

CVE-2026-0086
MEDIUM 6.8 Local

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalati…

CVE-2026-0085
MEDIUM 5.5 Local

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to …

CVE-2026-0080
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0079
MEDIUM 5.5 Local

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local deni…

CVE-2026-0075
MEDIUM 5.9 Local

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no…

CVE-2026-0074
MEDIUM 5.5 Local

In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of s…

CVE-2026-0070
MEDIUM 5.5 Local

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This coul…

CVE-2026-0069
MEDIUM 5.5 Local

In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with n…

CVE-2026-0067
MEDIUM 5.5 Local

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This coul…

CVE-2026-0061
MEDIUM 5.9 Local

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could l…

CVE-2026-0060
MEDIUM 5.5 Local

In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lea…

CVE-2026-0055
MEDIUM 6.2 Local

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a pat…

CVE-2026-0052
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0051
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remot…

CVE-2026-0048
MEDIUM 6.8 Local

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local …

CVE-2026-0046
MEDIUM 6.2 Local

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead …

CVE-2026-0044
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote…

CVE-2026-0043
MEDIUM 5.5 Local

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local esca…

CVE-2026-0042
MEDIUM 5.5 Local

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local deni…

CVE-2026-0041
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service …

CVE-2026-0040
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0039
MEDIUM 6.5 Réseau

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote den…