Vulnérabilités
Vulnérabilités des apps suivies
778 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-43543
MEDIUM 6.1
Réseau 1 apps
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects… |
|
CVE-2021-43542
MEDIUM 6.5
Réseau 1 apps
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff… |
|
CVE-2021-43541
MEDIUM 6.5
Réseau 1 apps
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder… |
|
CVE-2021-43538
MEDIUM 4.3
Réseau 1 apps
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock… |
|
CVE-2021-43536
MEDIUM 6.5
Réseau 1 apps
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < … |
|
CVE-2021-43528
MEDIUM 6.5
Réseau 1 apps
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level… |
|
CVE-2021-38509
MEDIUM 4.3
Réseau 1 apps
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a… |
|
CVE-2021-38508
MEDIUM 4.3
Réseau 1 apps
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav… |
|
CVE-2021-38507
MEDIUM 6.5
Réseau 1 apps
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT… |
|
CVE-2021-38506
MEDIUM 4.3
Réseau 1 apps
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on… |
|
CVE-2021-38505
MEDIUM 6.5
Réseau 1 apps
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it… |
|
CVE-2021-38502
MEDIUM 5.9
Réseau 1 apps
Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted mes… |
|
CVE-2021-38497
MEDIUM 6.5
Réseau 1 apps
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusi… |
|
CVE-2021-38492
MEDIUM 6.5
Réseau 1 apps
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in In… |
|
CVE-2021-38637
MEDIUM 5.5
Local
Windows Storage Information Disclosure Vulnerability |
|
CVE-2021-38636
MEDIUM 5.5
Local
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
|
CVE-2021-38635
MEDIUM 5.5
Local
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
|
CVE-2021-38632
MEDIUM 5.7
Physique
Windows BitLocker Security Feature Bypass Vulnerability |
|
CVE-2021-38629
MEDIUM 6.5
Réseau
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability |
|
CVE-2021-38624
MEDIUM 6.5
Réseau
Windows Key Storage Provider Security Feature Bypass Vulnerability |
|
CVE-2021-36972
MEDIUM 5.5
Local
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-36969
MEDIUM 5.5
Local
Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability |
|
CVE-2021-36962
MEDIUM 5.5
Local
Windows Installer Information Disclosure Vulnerability |
|
CVE-2021-36961
MEDIUM 5.5
Local
Windows Installer Denial of Service Vulnerability |
|
CVE-2021-36959
MEDIUM 5.5
Local
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-40529
MEDIUM 5.9
Réseau 1 apps
The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between tw… |
|
CVE-2021-29987
MEDIUM 6.5
Réseau 1 apps
After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still… |
|
CVE-2021-29982
MEDIUM 6.5
Réseau 1 apps
Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a single bit of memory. Th… |
|
CVE-2021-36938
MEDIUM 5.5
Local
Windows Cryptographic Primitives Library Information Disclosure Vulnerability |
|
CVE-2021-34534
MEDIUM 6.8
Réseau
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34480
MEDIUM 6.8
Réseau
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-29969
MEDIUM 5.9
Réseau 1 apps
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completion of the STARTTLS ha… |
|
CVE-2021-34466
MEDIUM 5.7
Physique
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2021-34457
MEDIUM 5.5
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-34454
MEDIUM 5.5
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-34448
MEDIUM 6.8
KEV
Réseau
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-34447
MEDIUM 6.8
Réseau
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34444
MEDIUM 6.5
Réseau
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-34440
MEDIUM 5.5
Local
GDI+ Information Disclosure Vulnerability |
|
CVE-2021-34509
MEDIUM 5.5
Local
Storage Spaces Controller Information Disclosure Vulnerability |
|
CVE-2021-34507
MEDIUM 6.5
Réseau
Windows Remote Assistance Information Disclosure Vulnerability |
|
CVE-2021-34500
MEDIUM 6.3
Réseau
Windows Kernel Memory Information Disclosure Vulnerability |
|
CVE-2021-34499
MEDIUM 6.5
Réseau
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-34497
MEDIUM 6.8
Réseau
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2021-34496
MEDIUM 5.5
Local
Windows GDI Information Disclosure Vulnerability |
|
CVE-2021-34493
MEDIUM 6.7
Local
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2021-34491
MEDIUM 5.5
Local
Win32k Information Disclosure Vulnerability |
|
CVE-2021-33783
MEDIUM 6.5
Réseau
Windows SMB Information Disclosure Vulnerability |
|
CVE-2021-33782
MEDIUM 5.5
Local
Windows Authenticode Spoofing Vulnerability |
|
CVE-2021-33765
MEDIUM 6.2
Local
Windows Installer Spoofing Vulnerability |