Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

15 629 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2025-24855
HIGH 7.8

numbers.c in libxslt before 1.1.43 has a use-after-free because, in nested XPath evaluations, an XPath context node can be modified but never restored. This is…

CVE-2025-24084
CRITICAL 8.4

Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability

CVE-2025-24076
HIGH 7.3

Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability

CVE-2025-24072
HIGH 7.8

Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability

CVE-2025-24071
HIGH 6.5

Microsoft Windows File Explorer Spoofing Vulnerability

CVE-2025-24067
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24066
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24064
CRITICAL 8.1

Windows Domain Name Service Remote Code Execution Vulnerability

CVE-2025-24061
HIGH 7.8

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2025-24059
HIGH 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2025-24056
HIGH 8.8

Windows Telephony Service Remote Code Execution Vulnerability

CVE-2025-24055
HIGH 4.3

Windows USB Video Class System Driver Information Disclosure Vulnerability

CVE-2025-24054
HIGH 6.5 KEV

NTLM Hash Disclosure Spoofing Vulnerability

CVE-2025-24051
HIGH 8.8

Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

CVE-2025-24050
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24048
HIGH 7.8

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2025-24046
HIGH 7.8

Kernel Streaming Service Driver Elevation of Privilege Vulnerability

CVE-2025-24045
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24044
HIGH 7.8

Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability

CVE-2025-24035
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-21247
HIGH 4.3

MapUrlToZone Security Feature Bypass Vulnerability

CVE-2025-21180
HIGH 7.8

Windows exFAT File System Remote Code Execution Vulnerability

CVE-2024-9157
HIGH

Synaptics: CVE-2024-9157 Synaptics Service Binaries DLL Loading Vulnerability

CVE-2024-55549
HIGH 7.8

xsltGetInheritedNsList in libxslt before 1.1.43 has a use-after-free issue

CVE-2025-26696
HIGH 7.0 Réseau 1 apps

Certain crafted MIME email messages that claimed to contain an encrypted OpenPGP message, which instead contained an OpenPGP signed message, were wrongly shown…

CVE-2025-26695
MEDIUM 5.3 Local 1 apps

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai…

CVE-2024-54560
MEDIUM 5.5 Local

A logic issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, watchOS 11. A malicious app may be ab…

CVE-2024-54558
LOW 2.8 Local

A clickjacking issue was addressed with improved out-of-process view handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be abl…

CVE-2024-54546
HIGH 7.5 Réseau

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15. An app may be able to cause unexpected system termination or co…

CVE-2024-54473
MEDIUM 5.5 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to access user-sensitive…

CVE-2024-54469
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2.…

CVE-2024-54467
MEDIUM 6.5 Réseau

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visi…

CVE-2024-54463
MEDIUM 5.5 Local

This issue was addressed with improved entitlements. This issue is fixed in macOS Sequoia 15. An app may be able to access removable volumes without user conse…

CVE-2024-44227
HIGH 7.5 Réseau

The issue was addressed with improved memory handling. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An app may be able to cause unexpected sy…

CVE-2024-44192
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in Safari 18, iOS 18 and iPadOS 18, macOS Sequoia 15, tvOS 18, visionOS 2, watchOS 11. Proces…

CVE-2024-44179
LOW 2.4 Physique

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoi…

CVE-2025-1943
HIGH 8.2 Réseau 1 apps

Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-1942
CRITICAL 9.8 Réseau 1 apps

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability …

CVE-2025-1938
MEDIUM 6.5 Réseau 1 apps

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1937
HIGH 7.5 Réseau 1 apps

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of…

CVE-2025-1936
HIGH 7.3 Réseau 1 apps

jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but…

CVE-2025-1935
MEDIUM 4.3 Réseau 1 apps

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR…

CVE-2025-1934
MEDIUM 6.5 Réseau 1 apps

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no…

CVE-2025-1933
HIGH 7.6 Réseau 1 apps

On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a di…

CVE-2025-1932
HIGH 8.1 Réseau 1 apps

An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This …

CVE-2025-1931
HIGH 7.5 Réseau 1 apps

It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerabil…

CVE-2025-1930
HIGH 8.8 Réseau 1 apps

On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led t…

CVE-2025-26417
HIGH

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-22413
HIGH

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-22412
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.