Vulnérabilités
Vulnérabilités des apps suivies
1 821 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-11704
CRITICAL 9.8
Réseau 1 apps
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key c… |
|
CVE-2024-11698
CRITICAL 9.8
Réseau 1 apps
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened durin… |
|
CVE-2024-11693
CRITICAL 9.8
Réseau 1 apps
The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating … |
|
CVE-2024-43639
CRITICAL 9.8
Windows KDC Proxy Remote Code Execution Vulnerability |
|
CVE-2024-43625
CRITICAL 8.1
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability |
|
CVE-2024-38408
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-44217
CRITICAL 9.1
Réseau
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in iOS 18 and iPadOS 18. Password autofill may … |
|
CVE-2024-40867
CRITICAL 9.6
Réseau
A custom URL scheme handling issue was addressed with improved input validation. This issue is fixed in iOS 18.1 and iPadOS 18.1. A remote attacker may be able… |
|
CVE-2024-44206
CRITICAL 9.3
Réseau
An issue in the handling of URL protocols was addressed with improved logic. This issue is fixed in Safari 17.6, iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, t… |
|
CVE-2024-9680
CRITICAL 9.8
KEV
Réseau 1 apps
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulner… |
|
CVE-2024-43582
CRITICAL 8.1
Remote Desktop Protocol Server Remote Code Execution Vulnerability |
|
CVE-2024-9402
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-9401
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2024-9392
CRITICAL 9.8
Réseau 1 apps
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3… |
|
CVE-2024-44148
CRITICAL 10.0
Réseau
This issue was addressed with improved validation of file attributes. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox. |
|
CVE-2024-44146
CRITICAL 10.0
Réseau
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox. |
|
CVE-2024-8387
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-33052
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-33042
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-38160
CRITICAL 9.1
Windows Network Virtualization Remote Code Execution Vulnerability |
|
CVE-2024-38159
CRITICAL 9.1
Windows Network Virtualization Remote Code Execution Vulnerability |
|
CVE-2024-38140
CRITICAL 9.8
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
|
CVE-2024-38063
CRITICAL 9.8
Windows TCP/IP Remote Code Execution Vulnerability |
|
CVE-2024-7519
CRITICAL 9.6
Réseau 1 apps
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox esc… |
|
CVE-2024-23350
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-6611
CRITICAL 9.8
Réseau 1 apps
A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128. |
|
CVE-2024-6606
CRITICAL 9.8
Réseau 1 apps
Clipboard code failed to check the index on an array access. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 128 and Thunder… |
|
CVE-2024-6602
CRITICAL 9.8
Réseau 1 apps
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird <… |
|
CVE-2024-6387
CRITICAL 8.1
RedHat Openssh: CVE-2024-6387 Remote Code Execution Due To A Race Condition In Signal Handling |
|
CVE-2024-38077
CRITICAL 9.8
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38076
CRITICAL 9.8
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38074
CRITICAL 9.8
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38060
CRITICAL 8.8
Windows Imaging Component Remote Code Execution Vulnerability |
|
CVE-2020-8597
CRITICAL 9.8
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2024-38476
CRITICAL 9.8
Réseau
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend application… |
|
CVE-2024-31320
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-21461
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-30080
CRITICAL 9.8
Réseau
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2019-8457
CRITICAL 9.8
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2023-43556
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-43551
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-43538
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-27280
CRITICAL 9.8
Réseau
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods … |
|
CVE-2024-4558
CRITICAL 9.6
Réseau
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2024-23706
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-3863
CRITICAL 9.8
Réseau 1 apps
The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating syst… |
|
CVE-2023-28582
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2024-21408
CRITICAL 5.5
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-21407
CRITICAL 8.1
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2024-23717
CRITICAL
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |