Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 297 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2025-46306
MEDIUM 5.5 Local

The issue was addressed with improved bounds checks. This issue is fixed in Keynote 15.1, iOS 26 and iPadOS 26, macOS Tahoe 26. Processing a maliciously crafte…

CVE-2026-0818
MEDIUM 4.3 Réseau 1 apps

When a user explicitly requested Thunderbird to decrypt an inline OpenPGP message that was embedded in a text section of an email that was formatted and styled…

CVE-2025-12781
MEDIUM 5.3 Réseau 1 apps

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepte…

CVE-2025-43508
MEDIUM 5.5 Local

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.

CVE-2025-24089
MEDIUM 5.3 Réseau

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3. An app may be able to enumerate a user's insta…

CVE-2026-21265
MEDIUM 6.4 Local

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affect…

CVE-2026-20962
MEDIUM 4.4 Local

Use of uninitialized resource in Dynamic Root of Trust for Measurement (DRTM) allows an authorized attacker to disclose information locally.

CVE-2026-20939
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20937
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20936
MEDIUM 4.3 Physique

Out-of-bounds read in Windows NDIS allows an authorized attacker to disclose information with a physical attack.

CVE-2026-20935
MEDIUM 6.2 Local

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an unauthorized attacker to disclose information locally.

CVE-2026-20932
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20927
MEDIUM 5.3 Réseau

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service…

CVE-2026-20925
MEDIUM 6.5 Réseau

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20876
MEDIUM 6.7 Local

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20872
MEDIUM 6.5 Réseau

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20862
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVE-2026-20851
MEDIUM 6.2 Local

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

CVE-2026-20847
MEDIUM 6.5 Réseau

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVE-2026-20839
MEDIUM 5.5 Local

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

CVE-2026-20838
MEDIUM 5.5 Local

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-20835
MEDIUM 5.5 Local

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

CVE-2026-20834
MEDIUM 4.6 Physique

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

CVE-2026-20829
MEDIUM 5.5 Local

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

CVE-2026-20828
MEDIUM 4.6 Physique

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-20827
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform…

CVE-2026-20825
MEDIUM 4.4 Local

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-20824
MEDIUM 5.5 Local

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-20823
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20821
MEDIUM 6.2 Local

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

CVE-2026-20819
MEDIUM 5.5 Local

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-20812
MEDIUM 6.5 Réseau

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

CVE-2026-20805
MEDIUM 5.5 KEV Local

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2026-0890
MEDIUM 5.4 Réseau 1 apps

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunder…

CVE-2026-0888
MEDIUM 5.3 Réseau 1 apps

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVE-2026-0887
MEDIUM 4.3 Réseau 1 apps

Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th…

CVE-2026-0886
MEDIUM 5.3 Réseau 1 apps

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a…

CVE-2026-0885
MEDIUM 6.5 Réseau 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2026-0883
MEDIUM 5.3 Réseau 1 apps

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2025-46299
MEDIUM 4.3 Réseau

A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS…

CVE-2025-46298
MEDIUM 6.5 Réseau

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2…

CVE-2025-46297
MEDIUM 5.5 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected files within an…

CVE-2025-46286
MEDIUM 4.3 Réseau

A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a backup may prevent passcode from being …

CVE-2025-62224
MEDIUM 5.5 Réseau 1 apps

User interface (ui) misrepresentation of critical information in Microsoft Edge for Android allows an authorized attacker to perform spoofing over a network.

CVE-2025-46292
MEDIUM 5.5 Local

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2. An app may be able …

CVE-2025-46288
MEDIUM 5.5 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2.…

CVE-2025-46283
MEDIUM 5.5 Local

A logic issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to access sensitive user…

CVE-2025-46282
MEDIUM 5.5 Local

The issue was addressed with additional permissions checks. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. An app may be able to access sensitive user d…

CVE-2025-46278
MEDIUM 5.5 Local

The issue was addressed with improved handling of caches. This issue is fixed in macOS Tahoe 26.2. An app may be able to access protected user data.

CVE-2025-43541
MEDIUM 4.3 Réseau

A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, …