Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

778 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2019-9947
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u…

CVE-2019-9740
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u…

CVE-2018-18499
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to anothe…

CVE-2018-18494
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another sit…

CVE-2018-20251
MEDIUM 5.5 Local 1 apps

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNA…

CVE-2019-7317
MEDIUM 5.3 Réseau 1 apps

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

CVE-2018-12383
MEDIUM 5.5 Local 1 apps

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because t…

CVE-2018-12374
MEDIUM 4.3 Réseau 1 apps

Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects …

CVE-2018-12373
MEDIUM 6.5 Réseau 1 apps

dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderb…

CVE-2018-12372
MEDIUM 6.5 Réseau 1 apps

Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thu…

CVE-2018-12367
MEDIUM 4.3 Réseau 1 apps

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals…

CVE-2018-12366
MEDIUM 6.5 Réseau 1 apps

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private dat…

CVE-2018-12365
MEDIUM 6.5 Réseau 1 apps

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. Th…

CVE-2018-1061
MEDIUM 6.5 Réseau 1 apps

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker …

CVE-2018-5185
MEDIUM 6.5 Réseau 1 apps

Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

CVE-2018-5170
MEDIUM 4.3 Réseau 1 apps

It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is …

CVE-2018-5168
MEDIUM 5.3 Réseau 1 apps

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a m…

CVE-2018-5161
MEDIUM 4.3 Réseau 1 apps

Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 5…

CVE-2018-5117
MEDIUM 5.3 Réseau 1 apps

If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed U…

CVE-2017-7848
MEDIUM 5.3 Réseau 1 apps

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

CVE-2017-7847
MEDIUM 4.3 Réseau 1 apps

Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.

CVE-2017-7830
MEDIUM 6.5 Réseau 1 apps

The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs…

CVE-2017-7829
MEDIUM 5.3 Réseau 1 apps

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed i…

CVE-2017-7825
MEDIUM 5.3 Réseau 1 apps

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name …

CVE-2017-7823
MEDIUM 5.4 Réseau 1 apps

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keywo…

CVE-2017-7791
MEDIUM 5.3 Réseau 1 apps

On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoo…

CVE-2017-7782
MEDIUM 5.3 Réseau 1 apps

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This a…

CVE-2017-7764
MEDIUM 5.3 Réseau 1 apps

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as th…

CVE-2017-7763
MEDIUM 5.3 Réseau 1 apps

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing at…

CVE-2017-5466
MEDIUM 6.1 Réseau 1 apps

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "dat…

CVE-2017-5462
MEDIUM 5.3 Réseau 1 apps

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS libr…

CVE-2017-5451
MEDIUM 4.3 Réseau 1 apps

A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text dis…

CVE-2017-5426
MEDIUM 5.3 Réseau 1 apps

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and …

CVE-2017-5418
MEDIUM 5.3 Réseau 1 apps

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory…

CVE-2017-5414
MEDIUM 5.5 Local 1 apps

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disc…

CVE-2017-5408
MEDIUM 5.3 Réseau 1 apps

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential informa…

CVE-2017-5407
MEDIUM 6.5 Réseau 1 apps

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This c…

CVE-2017-5405
MEDIUM 5.3 Réseau 1 apps

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, F…

CVE-2017-5383
MEDIUM 5.3 Réseau 1 apps

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks i…

CVE-2016-9895
MEDIUM 6.1 Réseau 1 apps

Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects…

CVE-2016-9074
MEDIUM 5.9 Réseau 1 apps

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1.…

CVE-2016-5294
MEDIUM 5.5 Local 1 apps

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires…

CVE-2016-5291
MEDIUM 5.5 Local 1 apps

A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 4…

CVE-2017-17689
MEDIUM 5.9 Réseau 3 apps

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVE-2017-17688
MEDIUM 5.9 Réseau 1 apps

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: t…

CVE-2018-8116
MEDIUM 4.4

Microsoft Graphics Component Denial of Service Vulnerability

CVE-2018-1000117
MEDIUM 6.7 Local 1 apps

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that ca…

CVE-2017-18207
MEDIUM 6.5 Réseau 1 apps

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial…

CVE-2018-1000021
MEDIUM 5.0 Réseau 1 apps

GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuratio…

CVE-2017-15298
MEDIUM 5.5 Local 1 apps

Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository,…