Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

516 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-23216
HIGH 7.1 Local

A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may…

CVE-2024-0258
HIGH 8.6 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may …

CVE-2024-23296
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2024-23225
HIGH 7.8 KEV Local

A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Monterey…

CVE-2023-52356
HIGH 7.5 Réseau

A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a re…

CVE-2024-23222
HIGH 8.8 KEV Réseau

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS …

CVE-2024-23214
HIGH 8.8 Réseau

Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, …

CVE-2024-23213
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma…

CVE-2024-23212
HIGH 7.8 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, ma…

CVE-2024-23209
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.3. Processing web content may lead to arbitrary code execution.

CVE-2024-23208
HIGH 7.8 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may …

CVE-2024-23204
HIGH 7.5 Réseau

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.…

CVE-2024-23203
HIGH 7.5 Réseau

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, m…

CVE-2023-38545
HIGH

Hackerone: CVE-2023-38545 SOCKS5 heap buffer overflow

CVE-2023-39215
HIGH 7.1 Réseau 4 apps

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39214
HIGH 7.6 Réseau 4 apps

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-36535
HIGH 7.1 Réseau 4 apps

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network acc…

CVE-2023-31486
HIGH 8.1

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2023-34114
HIGH 7.4 Réseau 2 apps

Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor…

CVE-2023-27967
HIGH 8.6 Local 1 apps

The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or wi…

CVE-2023-31484
HIGH 8.1

CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

CVE-2023-28597
HIGH 8.3 Réseau adjacent 4 apps

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later …

CVE-2022-42797
HIGH 7.8 Local 1 apps

An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges.

CVE-2022-39260
HIGH 8.5 Réseau 2 apps

Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull fun…

CVE-2022-39253
HIGH 5.5 Local 2 apps

Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are …

CVE-2022-29187
HIGH 7.8 Local 2 apps

Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privil…

CVE-2022-26747
HIGH 7.8 Local 1 apps

This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges.

CVE-2022-24765
HIGH 6.0 Local 2 apps

Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties …

CVE-2022-22608
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22607
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22606
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22605
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22604
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22603
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22602
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2022-22601
HIGH 7.8 Local 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected…

CVE-2019-8840
HIGH 8.8 Réseau 1 apps

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary co…

CVE-2020-13428
HIGH 7.8 Local 1 apps

A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allow…

CVE-2019-8806
HIGH 7.8 Local 1 apps

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrar…

CVE-2019-8800
HIGH 7.8 Local 1 apps

A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrar…

CVE-2019-8739
HIGH 7.8 Local 1 apps

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to ar…

CVE-2019-8738
HIGH 7.8 Local 1 apps

A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to ar…

CVE-2019-8724
HIGH 8.8 Réseau 1 apps

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro…

CVE-2019-8723
HIGH 8.8 Réseau 1 apps

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro…

CVE-2019-8722
HIGH 8.8 Réseau 1 apps

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro…

CVE-2019-8721
HIGH 8.8 Réseau 1 apps

Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro…

CVE-2019-17051
HIGH 7.8 Local 1 apps

Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-cl…

CVE-2019-13567
HIGH 8.8 Réseau 1 apps

The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the h…

CVE-2019-10038
HIGH 7.8 Local 1 apps

Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.a…

CVE-2018-4357
HIGH 7.8 Local 1 apps

A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10.