Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

778 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2021-33764
MEDIUM 5.9 Réseau

Windows Key Distribution Center Information Disclosure Vulnerability

CVE-2021-33763
MEDIUM 5.5 Local

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2021-33760
MEDIUM 5.5 Local

Media Foundation Information Disclosure Vulnerability

CVE-2021-33757
MEDIUM 5.3 Réseau

Windows Security Account Manager Remote Protocol Security Feature Bypass Vulnerability

CVE-2021-33755
MEDIUM 6.3 Réseau

Windows Hyper-V Denial of Service Vulnerability

CVE-2021-33745
MEDIUM 6.5 Réseau

Windows DNS Server Denial of Service Vulnerability

CVE-2021-33744
MEDIUM 5.3 Local

Windows Secure Kernel Mode Security Feature Bypass Vulnerability

CVE-2021-31961
MEDIUM 6.1 Local

Windows InstallService Elevation of Privilege Vulnerability

CVE-2021-29957
MEDIUM 4.3 Réseau 1 apps

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi…

CVE-2021-29956
MEDIUM 4.3 Réseau 1 apps

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass…

CVE-2021-29951
MEDIUM 6.5 Réseau 1 apps

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th…

CVE-2021-29945
MEDIUM 6.5 Réseau 1 apps

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32…

CVE-2021-23998
MEDIUM 6.5 Réseau 1 apps

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E…

CVE-2021-23993
MEDIUM 6.5 Réseau 1 apps

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub…

CVE-2021-23992
MEDIUM 4.3 Réseau 1 apps

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,…

CVE-2021-23991
MEDIUM 6.8 Réseau 1 apps

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b…

CVE-2021-3426
MEDIUM 5.7 Réseau adjacent 1 apps

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co…

CVE-2021-28312
MEDIUM 3.3

Windows NTFS Denial of Service Vulnerability

CVE-2021-23984
MEDIUM 6.5 Réseau 1 apps

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, …

CVE-2021-23982
MEDIUM 6.5 Réseau 1 apps

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on …

CVE-2020-7463
MEDIUM 5.5 Local 1 apps

In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handli…

CVE-2021-23953
MEDIUM 4.3 Réseau 1 apps

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as c…

CVE-2021-23973
MEDIUM 6.5 Réseau 1 apps

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed infor…

CVE-2021-23969
MEDIUM 4.3 Réseau 1 apps

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested …

CVE-2021-23968
MEDIUM 4.3 Réseau 1 apps

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to…

CVE-2021-23336
MEDIUM 5.9 Réseau 1 apps

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to W…

CVE-2021-24080
MEDIUM 6.5

Windows Trust Verification API Denial of Service Vulnerability

CVE-2020-35111
MEDIUM 4.3 Réseau 1 apps

When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web co…

CVE-2020-26978
MEDIUM 6.1 Réseau 1 apps

Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on …

CVE-2020-26966
MEDIUM 6.5 Réseau 1 apps

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res…

CVE-2020-26965
MEDIUM 6.5 Réseau 1 apps

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when…

CVE-2020-26961
MEDIUM 6.5 Réseau 1 apps

When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.…

CVE-2020-26958
MEDIUM 6.1 Réseau 1 apps

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a…

CVE-2020-26956
MEDIUM 6.1 Réseau 1 apps

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox …

CVE-2020-26953
MEDIUM 4.3 Réseau 1 apps

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other…

CVE-2020-26951
MEDIUM 6.1 Réseau 1 apps

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl…

CVE-2020-15646
MEDIUM 5.9 Réseau 1 apps

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attack…

CVE-2020-15677
MEDIUM 6.1 Réseau 1 apps

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original s…

CVE-2020-15676
MEDIUM 6.1 Réseau 1 apps

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attack…

CVE-2020-1574
MEDIUM 5.5 Local

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited…

CVE-2020-15658
MEDIUM 6.5 Réseau 1 apps

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p…

CVE-2020-15655
MEDIUM 6.5 Réseau 1 apps

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori…

CVE-2020-15654
MEDIUM 6.5 Réseau 1 apps

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are …

CVE-2020-15653
MEDIUM 6.5 Réseau 1 apps

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o…

CVE-2020-15652
MEDIUM 6.5 Réseau 1 apps

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content …

CVE-2020-15648
MEDIUM 6.5 Réseau 1 apps

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec…

CVE-2020-12421
MEDIUM 6.5 Réseau 1 apps

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) …

CVE-2020-12418
MEDIUM 6.5 Réseau 1 apps

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec…

CVE-2020-12405
MEDIUM 5.3 Réseau 1 apps

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects…

CVE-2020-12399
MEDIUM 4.4 Local 1 apps

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund…