Vulnérabilités
Vulnérabilités des apps suivies
778 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-33764
MEDIUM 5.9
Réseau
Windows Key Distribution Center Information Disclosure Vulnerability |
|
CVE-2021-33763
MEDIUM 5.5
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2021-33760
MEDIUM 5.5
Local
Media Foundation Information Disclosure Vulnerability |
|
CVE-2021-33757
MEDIUM 5.3
Réseau
Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability |
|
CVE-2021-33755
MEDIUM 6.3
Réseau
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-33745
MEDIUM 6.5
Réseau
Windows DNS Server Denial of Service Vulnerability |
|
CVE-2021-33744
MEDIUM 5.3
Local
Windows Secure Kernel Mode Security Feature Bypass Vulnerability |
|
CVE-2021-31961
MEDIUM 6.1
Local
Windows InstallService Elevation of Privilege Vulnerability |
|
CVE-2021-29957
MEDIUM 4.3
Réseau 1 apps
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi… |
|
CVE-2021-29956
MEDIUM 4.3
Réseau 1 apps
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass… |
|
CVE-2021-29951
MEDIUM 6.5
Réseau 1 apps
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th… |
|
CVE-2021-29945
MEDIUM 6.5
Réseau 1 apps
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32… |
|
CVE-2021-23998
MEDIUM 6.5
Réseau 1 apps
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E… |
|
CVE-2021-23993
MEDIUM 6.5
Réseau 1 apps
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub… |
|
CVE-2021-23992
MEDIUM 4.3
Réseau 1 apps
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,… |
|
CVE-2021-23991
MEDIUM 6.8
Réseau 1 apps
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b… |
|
CVE-2021-3426
MEDIUM 5.7
Réseau adjacent 1 apps
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co… |
|
CVE-2021-28312
MEDIUM 3.3
Windows NTFS Denial of Service Vulnerability |
|
CVE-2021-23984
MEDIUM 6.5
Réseau 1 apps
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, … |
|
CVE-2021-23982
MEDIUM 6.5
Réseau 1 apps
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on … |
|
CVE-2020-7463
MEDIUM 5.5
Local 1 apps
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handli… |
|
CVE-2021-23953
MEDIUM 4.3
Réseau 1 apps
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as c… |
|
CVE-2021-23973
MEDIUM 6.5
Réseau 1 apps
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed infor… |
|
CVE-2021-23969
MEDIUM 4.3
Réseau 1 apps
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested … |
|
CVE-2021-23968
MEDIUM 4.3
Réseau 1 apps
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to… |
|
CVE-2021-23336
MEDIUM 5.9
Réseau 1 apps
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to W… |
|
CVE-2021-24080
MEDIUM 6.5
Windows Trust Verification API Denial of Service Vulnerability |
|
CVE-2020-35111
MEDIUM 4.3
Réseau 1 apps
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web co… |
|
CVE-2020-26978
MEDIUM 6.1
Réseau 1 apps
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on … |
|
CVE-2020-26966
MEDIUM 6.5
Réseau 1 apps
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res… |
|
CVE-2020-26965
MEDIUM 6.5
Réseau 1 apps
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when… |
|
CVE-2020-26961
MEDIUM 6.5
Réseau 1 apps
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.… |
|
CVE-2020-26958
MEDIUM 6.1
Réseau 1 apps
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a… |
|
CVE-2020-26956
MEDIUM 6.1
Réseau 1 apps
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox … |
|
CVE-2020-26953
MEDIUM 4.3
Réseau 1 apps
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other… |
|
CVE-2020-26951
MEDIUM 6.1
Réseau 1 apps
A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl… |
|
CVE-2020-15646
MEDIUM 5.9
Réseau 1 apps
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attack… |
|
CVE-2020-15677
MEDIUM 6.1
Réseau 1 apps
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original s… |
|
CVE-2020-15676
MEDIUM 6.1
Réseau 1 apps
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attack… |
|
CVE-2020-1574
MEDIUM 5.5
Local
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited… |
|
CVE-2020-15658
MEDIUM 6.5
Réseau 1 apps
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p… |
|
CVE-2020-15655
MEDIUM 6.5
Réseau 1 apps
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori… |
|
CVE-2020-15654
MEDIUM 6.5
Réseau 1 apps
When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are … |
|
CVE-2020-15653
MEDIUM 6.5
Réseau 1 apps
An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o… |
|
CVE-2020-15652
MEDIUM 6.5
Réseau 1 apps
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content … |
|
CVE-2020-15648
MEDIUM 6.5
Réseau 1 apps
Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec… |
|
CVE-2020-12421
MEDIUM 6.5
Réseau 1 apps
When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) … |
|
CVE-2020-12418
MEDIUM 6.5
Réseau 1 apps
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec… |
|
CVE-2020-12405
MEDIUM 5.3
Réseau 1 apps
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects… |
|
CVE-2020-12399
MEDIUM 4.4
Local 1 apps
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund… |