Vulnérabilités
Vulnérabilités des apps suivies
778 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2020-14422
MEDIUM 5.9
Réseau 1 apps
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to… |
|
CVE-2020-13631
MEDIUM 5.5
Local 1 apps
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
|
CVE-2020-12392
MEDIUM 5.5
Local 1 apps
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user … |
|
CVE-2020-13434
MEDIUM 5.5
Local 1 apps
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
|
CVE-2020-12397
MEDIUM 4.3
Réseau 1 apps
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerab… |
|
CVE-2020-11008
MEDIUM 4.0
Réseau 1 apps
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is simi… |
|
CVE-2020-0935
MEDIUM 5.5
Local 1 apps
An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows E… |
|
CVE-2020-11765
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, le… |
|
CVE-2020-11764
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. |
|
CVE-2020-11763
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp. |
|
CVE-2020-11762
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling th… |
|
CVE-2020-11761
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfF… |
|
CVE-2020-11760
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp. |
|
CVE-2020-11759
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineB… |
|
CVE-2020-11758
MEDIUM 5.5
Local 1 apps
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. |
|
CVE-2020-6812
MEDIUM 5.3
Réseau 1 apps
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microp… |
|
CVE-2020-6798
MEDIUM 6.1
Réseau 1 apps
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that … |
|
CVE-2020-6797
MEDIUM 4.3
Réseau 1 apps
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is re… |
|
CVE-2020-6795
MEDIUM 6.5
Réseau 1 apps
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploi… |
|
CVE-2020-6794
MEDIUM 6.5
Réseau 1 apps
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is becau… |
|
CVE-2020-6793
MEDIUM 6.5
Réseau 1 apps
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird… |
|
CVE-2020-6792
MEDIUM 4.3
Réseau 1 apps
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 6… |
|
CVE-2020-8492
MEDIUM 6.5
Réseau 1 apps
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression … |
|
CVE-2020-8315
MEDIUM 5.5
Local 1 apps
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacke… |
|
CVE-2014-3753
MEDIUM 5.5
Local 1 apps
AgileBits 1Password through 1.0.9.340 allows security feature bypass |
|
CVE-2019-11763
MEDIUM 6.1
Réseau 1 apps
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML commen… |
|
CVE-2019-11762
MEDIUM 6.1
Réseau 1 apps
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on … |
|
CVE-2019-11761
MEDIUM 5.4
Réseau 1 apps
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this o… |
|
CVE-2019-8719
MEDIUM 6.1
Réseau 1 apps
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2019-8625
MEDIUM 6.1
Réseau 1 apps
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2016-1000110
MEDIUM 6.1
Réseau 1 apps
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker t… |
|
CVE-2019-11135
MEDIUM 6.5
Local
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via … |
|
CVE-2019-18348
MEDIUM 6.1
Réseau 1 apps
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a u… |
|
CVE-2019-16935
MEDIUM 6.1
Réseau 1 apps
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/Do… |
|
CVE-2019-11744
MEDIUM 6.1
Réseau 1 apps
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a li… |
|
CVE-2019-11742
MEDIUM 6.5
Réseau 1 apps
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an err… |
|
CVE-2019-11739
MEDIUM 6.5
Réseau 1 apps
Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunde… |
|
CVE-2019-9817
MEDIUM 5.3
Réseau 1 apps
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violati… |
|
CVE-2019-9816
MEDIUM 5.9
Réseau 1 apps
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch… |
|
CVE-2019-11730
MEDIUM 6.5
Réseau 1 apps
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo… |
|
CVE-2019-11717
MEDIUM 5.3
Réseau 1 apps
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible … |
|
CVE-2019-11715
MEDIUM 6.1
Réseau 1 apps
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa… |
|
CVE-2019-11698
MEDIUM 5.3
Réseau 1 apps
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten… |
|
CVE-2018-20852
MEDIUM 5.3
Réseau 1 apps
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se… |
|
CVE-2019-13118
MEDIUM 5.3
Réseau 1 apps
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination coul… |
|
CVE-2019-0948
MEDIUM 4.7
Windows Event Viewer Information Disclosure Vulnerability |
|
CVE-2018-18524
MEDIUM 6.1
Réseau 1 apps
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. Af… |
|
CVE-2019-9801
MEDIUM 5.3
Réseau 1 apps
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows o… |
|
CVE-2019-9793
MEDIUM 5.9
Réseau 1 apps
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnera… |
|
CVE-2018-18509
MEDIUM 5.3
Réseau 1 apps
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message… |