Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

778 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2020-14422
MEDIUM 5.9 Réseau 1 apps

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to…

CVE-2020-13631
MEDIUM 5.5 Local 1 apps

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVE-2020-12392
MEDIUM 5.5 Local 1 apps

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user …

CVE-2020-13434
MEDIUM 5.5 Local 1 apps

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

CVE-2020-12397
MEDIUM 4.3 Réseau 1 apps

By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerab…

CVE-2020-11008
MEDIUM 4.0 Réseau 1 apps

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is simi…

CVE-2020-0935
MEDIUM 5.5 Local 1 apps

An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows E…

CVE-2020-11765
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, le…

CVE-2020-11764
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

CVE-2020-11763
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

CVE-2020-11762
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling th…

CVE-2020-11761
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfF…

CVE-2020-11760
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

CVE-2020-11759
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineB…

CVE-2020-11758
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

CVE-2020-6812
MEDIUM 5.3 Réseau 1 apps

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microp…

CVE-2020-6798
MEDIUM 6.1 Réseau 1 apps

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that …

CVE-2020-6797
MEDIUM 4.3 Réseau 1 apps

By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is re…

CVE-2020-6795
MEDIUM 6.5 Réseau 1 apps

When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploi…

CVE-2020-6794
MEDIUM 6.5 Réseau 1 apps

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is becau…

CVE-2020-6793
MEDIUM 6.5 Réseau 1 apps

When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird…

CVE-2020-6792
MEDIUM 4.3 Réseau 1 apps

When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 6…

CVE-2020-8492
MEDIUM 6.5 Réseau 1 apps

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression …

CVE-2020-8315
MEDIUM 5.5 Local 1 apps

In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacke…

CVE-2014-3753
MEDIUM 5.5 Local 1 apps

AgileBits 1Password through 1.0.9.340 allows security feature bypass

CVE-2019-11763
MEDIUM 6.1 Réseau 1 apps

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML commen…

CVE-2019-11762
MEDIUM 6.1 Réseau 1 apps

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on …

CVE-2019-11761
MEDIUM 5.4 Réseau 1 apps

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this o…

CVE-2019-8719
MEDIUM 6.1 Réseau 1 apps

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win…

CVE-2019-8625
MEDIUM 6.1 Réseau 1 apps

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win…

CVE-2016-1000110
MEDIUM 6.1 Réseau 1 apps

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker t…

CVE-2019-11135
MEDIUM 6.5 Local

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via …

CVE-2019-18348
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a u…

CVE-2019-16935
MEDIUM 6.1 Réseau 1 apps

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/Do…

CVE-2019-11744
MEDIUM 6.1 Réseau 1 apps

Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a li…

CVE-2019-11742
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an err…

CVE-2019-11739
MEDIUM 6.5 Réseau 1 apps

Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunde…

CVE-2019-9817
MEDIUM 5.3 Réseau 1 apps

Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violati…

CVE-2019-9816
MEDIUM 5.9 Réseau 1 apps

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch…

CVE-2019-11730
MEDIUM 6.5 Réseau 1 apps

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo…

CVE-2019-11717
MEDIUM 5.3 Réseau 1 apps

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible …

CVE-2019-11715
MEDIUM 6.1 Réseau 1 apps

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa…

CVE-2019-11698
MEDIUM 5.3 Réseau 1 apps

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten…

CVE-2018-20852
MEDIUM 5.3 Réseau 1 apps

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se…

CVE-2019-13118
MEDIUM 5.3 Réseau 1 apps

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination coul…

CVE-2019-0948
MEDIUM 4.7

Windows Event Viewer Information Disclosure Vulnerability

CVE-2018-18524
MEDIUM 6.1 Réseau 1 apps

Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. Af…

CVE-2019-9801
MEDIUM 5.3 Réseau 1 apps

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows o…

CVE-2019-9793
MEDIUM 5.9 Réseau 1 apps

A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnera…

CVE-2018-18509
MEDIUM 5.3 Réseau 1 apps

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message…