Vulnérabilités
Vulnérabilités des apps suivies
778 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-29532
MEDIUM 5.5
Local 1 apps
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s… |
|
CVE-2023-34121
MEDIUM 4.1
Réseau 1 apps
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially… |
|
CVE-2023-28599
MEDIUM 4.3
Réseau 4 apps
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-33595
MEDIUM 5.5
Local 1 apps
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. |
|
CVE-2023-32212
MEDIUM 4.3
Réseau 1 apps
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb… |
|
CVE-2023-32211
MEDIUM 6.5
Réseau 1 apps
A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. |
|
CVE-2023-32206
MEDIUM 6.5
Réseau 1 apps
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102… |
|
CVE-2023-32205
MEDIUM 4.3
Réseau 1 apps
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac… |
|
CVE-2023-28164
MEDIUM 6.5
Réseau 1 apps
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af… |
|
CVE-2023-28163
MEDIUM 6.5
Réseau 1 apps
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those … |
|
CVE-2023-25752
MEDIUM 6.5
Réseau 1 apps
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code… |
|
CVE-2023-25751
MEDIUM 6.5
Réseau 1 apps
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially … |
|
CVE-2023-25742
MEDIUM 6.5
Réseau 1 apps
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T… |
|
CVE-2023-25738
MEDIUM 6.5
Réseau 1 apps
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo… |
|
CVE-2023-25730
MEDIUM 5.4
Réseau 1 apps
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result… |
|
CVE-2023-25728
MEDIUM 6.5
Réseau 1 apps
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t… |
|
CVE-2023-23603
MEDIUM 6.5
Réseau 1 apps
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da… |
|
CVE-2023-23602
MEDIUM 6.5
Réseau 1 apps
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co… |
|
CVE-2023-23601
MEDIUM 6.5
Réseau 1 apps
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability… |
|
CVE-2023-23599
MEDIUM 6.5
Réseau 1 apps
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands … |
|
CVE-2023-23598
MEDIUM 6.5
Réseau 1 apps
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou… |
|
CVE-2023-1945
MEDIUM 6.5
Réseau 1 apps
Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder… |
|
CVE-2023-0616
MEDIUM 6.5
Réseau 1 apps
If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T… |
|
CVE-2023-0547
MEDIUM 6.5
Réseau 1 apps
OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird v… |
|
CVE-2023-0430
MEDIUM 6.5
Réseau 1 apps
Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a vali… |
|
CVE-2023-27043
MEDIUM 5.3
Réseau 1 apps
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident… |
|
CVE-2023-22880
MEDIUM 6.8
Réseau 1 apps
Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an … |
|
CVE-2023-24880
MEDIUM 4.4
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2022-46880
MEDIUM 6.5
Réseau 1 apps
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13t… |
|
CVE-2022-46875
MEDIUM 6.5
Réseau 1 apps
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue onl… |
|
CVE-2022-45420
MEDIUM 6.5
Réseau 1 apps
Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user … |
|
CVE-2022-45418
MEDIUM 6.1
Réseau 1 apps
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user con… |
|
CVE-2022-45416
MEDIUM 6.5
Réseau 1 apps
Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have… |
|
CVE-2022-45411
MEDIUM 6.1
Réseau 1 apps
Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies in… |
|
CVE-2022-45410
MEDIUM 6.5
Réseau 1 apps
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This … |
|
CVE-2022-45408
MEDIUM 6.5
Réseau 1 apps
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in… |
|
CVE-2022-45405
MEDIUM 6.5
Réseau 1 apps
Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This … |
|
CVE-2022-45404
MEDIUM 6.5
Réseau 1 apps
Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification promp… |
|
CVE-2022-45403
MEDIUM 6.5
Réseau 1 apps
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range … |
|
CVE-2022-42929
MEDIUM 6.5
Réseau 1 apps
If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending… |
|
CVE-2022-40960
MEDIUM 6.5
Réseau 1 apps
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vul… |
|
CVE-2022-40959
MEDIUM 6.5
Réseau 1 apps
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted su… |
|
CVE-2022-40958
MEDIUM 6.5
Réseau 1 apps
By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies fro… |
|
CVE-2022-40957
MEDIUM 6.5
Réseau 1 apps
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM… |
|
CVE-2022-40956
MEDIUM 6.1
Réseau 1 apps
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability … |
|
CVE-2022-3266
MEDIUM 5.5
Local 1 apps
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thun… |
|
CVE-2022-3034
MEDIUM 4.3
Réseau 1 apps
When receiving an HTML email that specified to load an <code>iframe</code> element from a remote location, a request to the remote document was sent. However, … |
|
CVE-2022-3032
MEDIUM 6.5
Réseau 1 apps
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML document, remot… |
|
CVE-2022-38472
MEDIUM 6.5
Réseau 1 apps
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This cou… |
|
CVE-2022-36318
MEDIUM 5.3
Réseau 1 apps
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox E… |