Vulnérabilités
Vulnérabilités des apps suivies
2 300 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-0041
MEDIUM 6.5
Réseau
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service … |
|
CVE-2026-0040
MEDIUM 6.5
Réseau
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s… |
|
CVE-2026-0039
MEDIUM 6.5
Réseau
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote den… |
|
CVE-2026-0018
MEDIUM 5.5
Local
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead t… |
|
CVE-2025-48648
MEDIUM 5.5
Local
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with… |
|
CVE-2026-9309
MEDIUM 5.4
Réseau 1 apps
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and l… |
|
CVE-2026-9308
MEDIUM 5.4
Réseau 1 apps
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placehold… |
|
CVE-2026-20454
MEDIUM 6.4
Local
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has alread… |
|
CVE-2026-20453
MEDIUM 6.7
Local
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has … |
|
CVE-2026-9078
MEDIUM 5.4
Réseau 1 apps
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RT… |
|
CVE-2026-45585
MEDIUM 6.8
Physique
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-8706
MEDIUM 6.5
Réseau adjacent 1 apps
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receiv… |
|
CVE-2026-8971
MEDIUM 6.5
Réseau 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8961
MEDIUM 6.5
Réseau 1 apps
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-35429
MEDIUM 4.3
Réseau 1 apps
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net… |
|
CVE-2026-32170
MEDIUM 6.7
Local
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-43666
MEDIUM 6.2
Local
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS … |
|
CVE-2026-43659
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7,… |
|
CVE-2026-43653
MEDIUM 6.2
Local
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.8, mac… |
|
CVE-2026-39869
MEDIUM 4.3
Réseau
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, mac… |
|
CVE-2026-28996
MEDIUM 5.5
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Ta… |
|
CVE-2026-28994
MEDIUM 5.3
Réseau adjacent
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequ… |
|
CVE-2026-28993
MEDIUM 5.5
Local
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS … |
|
CVE-2026-28992
MEDIUM 4.7
Local
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Seq… |
|
CVE-2026-28988
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5.… |
|
CVE-2026-28985
MEDIUM 6.2
Local
A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5. An attac… |
|
CVE-2026-28977
MEDIUM 6.2
Local
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS… |
|
CVE-2026-28972
MEDIUM 6.5
Réseau
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS… |
|
CVE-2026-28971
MEDIUM 4.3
Réseau
The issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. A malicious i… |
|
CVE-2026-28967
MEDIUM 4.9
Réseau
A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4. An attac… |
|
CVE-2026-28963
MEDIUM 4.6
Physique
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to… |
|
CVE-2026-28961
MEDIUM 4.6
Physique
This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attacker with physical ac… |
|
CVE-2026-28958
MEDIUM 5.5
Local
This issue was addressed with improved data protection. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5. An app m… |
|
CVE-2026-28956
MEDIUM 6.5
Réseau
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.… |
|
CVE-2026-28946
MEDIUM 6.5
Réseau
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, macOS Tahoe 26.5. Processing maliciously crafted web … |
|
CVE-2026-28942
MEDIUM 6.5
Réseau
A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5… |
|
CVE-2026-28922
MEDIUM 6.5
Réseau
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be a… |
|
CVE-2026-28920
MEDIUM 6.5
Réseau
An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 1… |
|
CVE-2026-28918
MEDIUM 6.5
Réseau
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, vision… |
|
CVE-2026-28917
MEDIUM 4.3
Réseau
The issue was addressed with improved input validation. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe… |
|
CVE-2026-28914
MEDIUM 5.5
Local
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciously craf… |
|
CVE-2026-28903
MEDIUM 6.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe … |
|
CVE-2026-28902
MEDIUM 6.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5… |
|
CVE-2026-28901
MEDIUM 4.3
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5… |
|
CVE-2026-28897
MEDIUM 6.2
Local
A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15… |
|
CVE-2026-28830
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. |
|
CVE-2026-28819
MEDIUM 5.4
Réseau
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sono… |
|
CVE-2026-20696
MEDIUM 5.5
Local
An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data. |
|
CVE-2026-23866
MEDIUM 4.3
Réseau 2 apps
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26… |
|
CVE-2026-6019
MEDIUM 6.1
Réseau 1 apps
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sen… |