Vulnérabilités
Vulnérabilités des apps suivies
8 495 CVE touchent une app ou un OS suivi (toutes sévérités, Windows). 214 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 8 495
- Activement exploitées
- 214
- Fenêtre de publication
- 2002-10-04 → 2026-08-19
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-1651
HIGH 7.8
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2021-1650
HIGH 7.8
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability |
|
CVE-2021-1649
HIGH 7.8
Active Template Library Elevation of Privilege Vulnerability |
|
CVE-2021-1648
HIGH 7.8
Microsoft splwow64 Elevation of Privilege Vulnerability |
|
CVE-2021-1646
HIGH 6.6
Windows WLAN Service Elevation of Privilege Vulnerability |
|
CVE-2021-1645
HIGH 5.0
Windows Docker Information Disclosure Vulnerability |
|
CVE-2021-1642
HIGH 7.8
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability |
|
CVE-2021-1638
HIGH 7.7
Windows Bluetooth Security Feature Bypass Vulnerability |
|
CVE-2021-1637
HIGH 5.5
Windows DNS Query Information Disclosure Vulnerability |
|
CVE-2020-35113
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presu… |
|
CVE-2020-35112
HIGH 8.8
1 app
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads d… |
|
CVE-2020-35111
MEDIUM 4.3
1 app
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web co… |
|
CVE-2020-26978
MEDIUM 6.1
1 app
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on … |
|
CVE-2020-26974
HIGH 8.8
1 app
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-af… |
|
CVE-2020-26973
HIGH 8.8
1 app
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerab… |
|
CVE-2020-26971
HIGH 8.8
1 app
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Fire… |
|
CVE-2020-26970
HIGH 8.8
1 app
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on p… |
|
CVE-2020-26968
HIGH 8.8
1 app
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presu… |
|
CVE-2020-26966
MEDIUM 6.5
1 app
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res… |
|
CVE-2020-26965
MEDIUM 6.5
1 app
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when… |
|
CVE-2020-26961
MEDIUM 6.5
1 app
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.… |
|
CVE-2020-26960
HIGH 8.8
1 app
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free… |
|
CVE-2020-26959
HIGH 8.8
1 app
During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potent… |
|
CVE-2020-26958
MEDIUM 6.1
1 app
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a… |
|
CVE-2020-26956
MEDIUM 6.1
1 app
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox … |
|
CVE-2020-26953
MEDIUM 4.3
1 app
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other… |
|
CVE-2020-26951
MEDIUM 6.1
1 app
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl… |
|
CVE-2020-26950
HIGH 8.8
1 app
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerab… |
|
CVE-2020-27895
LOW 3.3
1 app
An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTune… |
|
CVE-2020-9999
HIGH 7.8
1 app
A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a m… |
|
CVE-2020-17140
HIGH 8.1
Windows SMB Information Disclosure Vulnerability |
|
CVE-2020-17139
HIGH 7.8
Windows Overlay Filter Security Feature Bypass Vulnerability |
|
CVE-2020-17138
HIGH 5.5
Windows Error Reporting Information Disclosure Vulnerability |
|
CVE-2020-17137
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2020-17136
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2020-17134
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2020-17103
HIGH 7.0
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2020-17099
HIGH 6.8
Windows Lock Screen Security Feature Bypass Vulnerability |
|
CVE-2020-17098
HIGH 5.5
Windows GDI+ Information Disclosure Vulnerability |
|
CVE-2020-17097
HIGH 3.3
Windows Digital Media Receiver Elevation of Privilege Vulnerability |
|
CVE-2020-17096
HIGH 7.5
Windows NTFS Remote Code Execution Vulnerability |
|
CVE-2020-17095
CRITICAL 8.5
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2020-17094
HIGH 5.5
Windows Error Reporting Information Disclosure Vulnerability |
|
CVE-2020-17092
HIGH 7.8
Windows Network Connections Service Elevation of Privilege Vulnerability |
|
CVE-2020-16996
HIGH 6.5
Kerberos Security Feature Bypass Vulnerability |
|
CVE-2020-16964
HIGH 7.8
Windows Backup Engine Elevation of Privilege Vulnerability |
|
CVE-2020-16963
HIGH 7.8
Windows Backup Engine Elevation of Privilege Vulnerability |
|
CVE-2020-16962
HIGH 7.8
Windows Backup Engine Elevation of Privilege Vulnerability |
|
CVE-2020-16961
HIGH 7.8
Windows Backup Engine Elevation of Privilege Vulnerability |
|
CVE-2020-16960
HIGH 7.8
Windows Backup Engine Elevation of Privilege Vulnerability |