Vulnérabilités
Vulnérabilités des apps suivies
905 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-23250
MEDIUM 5.5
Local
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A… |
|
CVE-2024-23241
MEDIUM 5.5
Local
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able t… |
|
CVE-2024-23239
MEDIUM 4.7
Local
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An ap… |
|
CVE-2024-23235
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tv… |
|
CVE-2024-23234
MEDIUM 6.7
Local
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.… |
|
CVE-2024-23231
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17… |
|
CVE-2024-23230
MEDIUM 5.5
Local
This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able… |
|
CVE-2024-23205
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app … |
|
CVE-2024-23201
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macO… |
|
CVE-2023-28826
MEDIUM 5.5
Local
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS So… |
|
CVE-2023-42853
MEDIUM 5.5
Local
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to … |
|
CVE-2024-24699
MEDIUM 6.5
Réseau 4 apps
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
MEDIUM 4.9
Réseau 4 apps
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |
|
CVE-2024-24690
MEDIUM 5.4
Réseau 4 apps
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2024-23224
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.3, macOS Ventura 13.6.4. An app may be able to access sensitive user data. |
|
CVE-2024-23223
MEDIUM 6.2
Local
A privacy issue was addressed with improved handling of files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An … |
|
CVE-2024-23218
MEDIUM 5.9
Réseau
A timing side-channel issue was addressed with improvements to constant-time computation in cryptographic functions. This issue is fixed in iOS 16.7.6 and iPad… |
|
CVE-2024-23215
MEDIUM 5.5
Local
An issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. … |
|
CVE-2024-23207
MEDIUM 5.5
Local
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma… |
|
CVE-2024-23206
MEDIUM 6.5
Réseau
An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, ma… |
|
CVE-2023-42937
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ve… |
|
CVE-2023-42935
MEDIUM 5.5
Local
An authentication issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.6.4. A local attacker may be able to view the pre… |
|
CVE-2023-42888
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS… |
|
CVE-2023-42887
MEDIUM 6.3
Local
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Ventura 13.6.4, macOS Sonoma 14.2. An app may be able to read … |
|
CVE-2023-40528
MEDIUM 5.5
Local
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17, watchOS 10, macOS Sonoma 14, iOS 17 and iPadOS 17, macOS Ventura 13.6… |
|
CVE-2022-42816
MEDIUM 5.5
Local
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file s… |
|
CVE-2023-51384
MEDIUM 5.5
Local
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of … |
|
CVE-2023-49646
MEDIUM 6.4
Réseau 4 apps
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-43582
MEDIUM 5.5
Réseau 4 apps
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
|
CVE-2023-39205
MEDIUM 4.3
Réseau 4 apps
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-39204
MEDIUM 4.3
Réseau 4 apps
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-39199
MEDIUM 4.9
Réseau 4 apps
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. |
|
CVE-2023-42861
MEDIUM 6.5
Réseau
A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentia… |
|
CVE-2023-40435
MEDIUM 5.5
Local 1 apps
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. |
|
CVE-2022-32920
MEDIUM 5.5
Local 1 apps
The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information. |
|
CVE-2023-39218
MEDIUM 6.1
Réseau 4 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-36532
MEDIUM 5.9
Réseau 4 apps
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
|
CVE-2023-36539
MEDIUM 5.3
Réseau 4 apps
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-32395
MEDIUM 5.5
Local
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may … |
|
CVE-2023-28600
MEDIUM 5.2
Local 1 apps
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten… |
|
CVE-2023-28599
MEDIUM 4.3
Réseau 4 apps
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-27952
MEDIUM 4.7
Local
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks. |
|
CVE-2023-27945
MEDIUM 6.3
Local 1 apps
This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be abl… |
|
CVE-2023-27043
MEDIUM 5.3
Réseau 1 apps
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident… |
|
CVE-2022-32550
MEDIUM 4.8
Réseau 4 apps
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic… |
|
CVE-2022-29868
MEDIUM 5.5
Local 1 apps
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate… |
|
CVE-2021-41795
MEDIUM 6.5
Réseau 1 apps
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable compo… |
|
CVE-2021-1800
MEDIUM 5.5
Local 1 apps
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files … |
|
CVE-2019-20372
MEDIUM 5.3
Réseau 1 apps
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized … |
|
CVE-2019-13450
MEDIUM 6.5
Réseau 1 apps
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.… |