Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

571 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2021-30496
MEDIUM 5.7 Réseau 1 apps

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied mes…

CVE-2021-24114
MEDIUM 5.7 Réseau 1 apps

Microsoft Teams iOS Information Disclosure Vulnerability

CVE-2021-27205
MEDIUM 5.5 Local 2 apps

Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

CVE-2021-27204
MEDIUM 5.5 Local 2 apps

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

CVE-2020-1908
MEDIUM 4.6 Physique 1 apps

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact wit…

CVE-2020-1904
MEDIUM 5.5 Local 1 apps

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwr…

CVE-2020-1903
MEDIUM 5.5 Local 1 apps

An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulte…

CVE-2020-1901
MEDIUM 5.3 Réseau 1 apps

Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.

CVE-2020-12474
MEDIUM 6.5 Réseau 2 apps

Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public U…

CVE-2019-14319
MEDIUM 6.5 Réseau adjacent 2 apps

The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker…

CVE-2019-15514
MEDIUM 5.3 Réseau 2 apps

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attac…

CVE-2019-1948
MEDIUM 5.9 Réseau 1 apps

A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by usin…

CVE-2019-1218
MEDIUM 5.4 Réseau 1 apps

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit t…

CVE-2019-1084
MEDIUM 6.5 Réseau 2 apps

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated a…

CVE-2018-6976
MEDIUM 5.3 Réseau 1 apps

The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted file…

CVE-2018-12271
MEDIUM 6.4 Physique 1 apps

An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by…

CVE-2017-17689
MEDIUM 5.9 Réseau 3 apps

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVE-2018-6849
MEDIUM 4.3 Réseau 2 apps

In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), th…

CVE-2016-10511
MEDIUM 5.9 Réseau 1 apps

The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitti…

CVE-2016-4075
MEDIUM 6.1 Réseau 2 apps

Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.

CVE-2017-2391
MEDIUM 5.3 Réseau 9 apps

An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3…