Vulnérabilités
Vulnérabilités des apps suivies
7 804 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-29367
HIGH 7.8
iSCSI Target WMI Provider Remote Code Execution Vulnerability |
|
CVE-2023-29366
HIGH 7.8
Windows Geolocation Service Remote Code Execution Vulnerability |
|
CVE-2023-29365
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-29364
HIGH 7.0
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2023-29363
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-29362
HIGH 8.8
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2023-29361
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-29360
HIGH 8.4
KEV
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-29359
HIGH 7.8
GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29358
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29355
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-29352
HIGH 6.5
Windows Remote Desktop Security Feature Bypass Vulnerability |
|
CVE-2023-29351
HIGH 8.1
Windows Group Policy Elevation of Privilege Vulnerability |
|
CVE-2023-29346
HIGH 7.8
NTFS Elevation of Privilege Vulnerability |
|
CVE-2023-24938
HIGH 6.5
Windows CryptoAPI Denial of Service Vulnerability |
|
CVE-2023-24937
HIGH 6.5
Windows CryptoAPI Denial of Service Vulnerability |
|
CVE-2023-33595
MEDIUM 5.5
Local 2 apps
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. |
|
CVE-2023-32215
HIGH 8.8
Réseau 1 apps
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team repor… |
|
CVE-2023-32213
HIGH 8.8
Réseau 1 apps
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird… |
|
CVE-2023-32212
MEDIUM 4.3
Réseau 1 apps
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb… |
|
CVE-2023-32211
MEDIUM 6.5
Réseau 1 apps
A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. |
|
CVE-2023-32207
HIGH 8.8
Réseau 1 apps
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefo… |
|
CVE-2023-32206
MEDIUM 6.5
Réseau 1 apps
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102… |
|
CVE-2023-32205
MEDIUM 4.3
Réseau 1 apps
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac… |
|
CVE-2023-28176
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort… |
|
CVE-2023-28164
MEDIUM 6.5
Réseau 1 apps
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af… |
|
CVE-2023-28163
MEDIUM 6.5
Réseau 1 apps
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those … |
|
CVE-2023-28162
HIGH 8.8
Réseau 1 apps
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash.… |
|
CVE-2023-25752
MEDIUM 6.5
Réseau 1 apps
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code… |
|
CVE-2023-25751
MEDIUM 6.5
Réseau 1 apps
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially … |
|
CVE-2023-25746
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c… |
|
CVE-2023-25742
MEDIUM 6.5
Réseau 1 apps
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T… |
|
CVE-2023-25739
HIGH 8.8
Réseau 1 apps
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. Th… |
|
CVE-2023-25738
MEDIUM 6.5
Réseau 1 apps
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo… |
|
CVE-2023-25737
HIGH 8.8
Réseau 1 apps
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Th… |
|
CVE-2023-25735
HIGH 8.8
Réseau 1 apps
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-… |
|
CVE-2023-25734
HIGH 8.1
Réseau 1 apps
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network … |
|
CVE-2023-25732
HIGH 8.8
Réseau 1 apps
When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading … |
|
CVE-2023-25730
MEDIUM 5.4
Réseau 1 apps
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result… |
|
CVE-2023-25729
HIGH 8.8
Réseau 1 apps
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user… |
|
CVE-2023-25728
MEDIUM 6.5
Réseau 1 apps
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t… |
|
CVE-2023-23605
HIGH 8.8
Réseau 1 apps
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of… |
|
CVE-2023-23603
MEDIUM 6.5
Réseau 1 apps
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da… |
|
CVE-2023-23602
MEDIUM 6.5
Réseau 1 apps
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co… |
|
CVE-2023-23601
MEDIUM 6.5
Réseau 1 apps
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability… |
|
CVE-2023-23599
MEDIUM 6.5
Réseau 1 apps
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands … |
|
CVE-2023-23598
MEDIUM 6.5
Réseau 1 apps
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou… |
|
CVE-2023-1945
MEDIUM 6.5
Réseau 1 apps
Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder… |
|
CVE-2023-0767
HIGH 8.8
Réseau 1 apps
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. … |
|
CVE-2023-0616
MEDIUM 6.5
Réseau 1 apps
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T… |