Vulnérabilités
Vulnérabilités des apps suivies
7 805 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-21560
HIGH 6.6
Windows Boot Manager Security Feature Bypass Vulnerability |
|
CVE-2023-21559
HIGH 5.5
Windows Cryptographic Information Disclosure Vulnerability |
|
CVE-2023-21558
HIGH 7.8
Windows Error Reporting Service Elevation of Privilege Vulnerability |
|
CVE-2023-21557
HIGH 7.5
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2023-21556
CRITICAL 8.1
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
|
CVE-2023-21555
CRITICAL 8.1
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
|
CVE-2023-21552
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-21551
CRITICAL 7.8
Microsoft Cryptographic Services Elevation of Privilege Vulnerability |
|
CVE-2023-21550
HIGH 5.5
Windows Cryptographic Information Disclosure Vulnerability |
|
CVE-2023-21549
HIGH 8.8
Windows SMB Witness Service Elevation of Privilege Vulnerability |
|
CVE-2023-21548
CRITICAL 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
|
CVE-2023-21547
HIGH 7.5
Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability |
|
CVE-2023-21546
CRITICAL 8.1
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
|
CVE-2023-21543
CRITICAL 8.1
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability |
|
CVE-2023-21542
HIGH 7.0
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2023-21541
HIGH 7.8
Windows Task Scheduler Elevation of Privilege Vulnerability |
|
CVE-2023-21540
HIGH 5.5
Windows Cryptographic Information Disclosure Vulnerability |
|
CVE-2023-21539
HIGH 7.5
Windows Authentication Remote Code Execution Vulnerability |
|
CVE-2023-21537
HIGH 7.8
Microsoft Message Queuing (MSMQ) Elevation of Privilege Vulnerability |
|
CVE-2023-21536
HIGH 4.7
Event Tracing for Windows Information Disclosure Vulnerability |
|
CVE-2023-21535
CRITICAL 8.1
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability |
|
CVE-2023-21532
HIGH 7.0
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-21527
HIGH 7.5
Windows iSCSI Service Denial of Service Vulnerability |
|
CVE-2023-21525
HIGH 5.3
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-21524
HIGH 7.8
Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability |
|
CVE-2022-23960
HIGH
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2022-46882
CRITICAL 9.8
Réseau 1 apps
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thun… |
|
CVE-2022-46881
HIGH 8.8
Réseau 1 apps
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was ad… |
|
CVE-2022-46880
MEDIUM 6.5
Réseau 1 apps
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13t… |
|
CVE-2022-46878
HIGH 8.8
Réseau 1 apps
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of th… |
|
CVE-2022-46875
MEDIUM 6.5
Réseau 1 apps
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue onl… |
|
CVE-2022-46874
HIGH 8.8
Réseau 1 apps
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potenti… |
|
CVE-2022-46872
HIGH 8.6
Réseau 1 apps
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug… |
|
CVE-2022-45421
HIGH 8.8
Réseau 1 apps
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory … |
|
CVE-2022-45420
MEDIUM 6.5
Réseau 1 apps
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user … |
|
CVE-2022-45418
MEDIUM 6.1
Réseau 1 apps
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user con… |
|
CVE-2022-45416
MEDIUM 6.5
Réseau 1 apps
Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have… |
|
CVE-2022-45414
HIGH 8.1
Réseau 1 apps
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the POSTER attribute or … |
|
CVE-2022-45412
HIGH 8.8
Réseau 1 apps
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing un… |
|
CVE-2022-45411
MEDIUM 6.1
Réseau 1 apps
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies in… |
|
CVE-2022-45410
MEDIUM 6.5
Réseau 1 apps
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This … |
|
CVE-2022-45409
HIGH 8.8
Réseau 1 apps
The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a u… |
|
CVE-2022-45408
MEDIUM 6.5
Réseau 1 apps
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in… |
|
CVE-2022-45406
CRITICAL 9.8
Réseau 1 apps
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. Thi… |
|
CVE-2022-45405
MEDIUM 6.5
Réseau 1 apps
Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This … |
|
CVE-2022-45404
MEDIUM 6.5
Réseau 1 apps
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification promp… |
|
CVE-2022-45403
MEDIUM 6.5
Réseau 1 apps
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range … |
|
CVE-2022-42932
HIGH 8.8
Réseau 1 apps
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed… |
|
CVE-2022-42929
MEDIUM 6.5
Réseau 1 apps
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending… |
|
CVE-2022-42928
HIGH 8.8
Réseau 1 apps
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potent… |