Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-42836
HIGH 7.0
Local
Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized atta… |
|
CVE-2026-42829
HIGH 7.8
Local
Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally. |
|
CVE-2026-42828
HIGH 7.8
Local
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-41108
HIGH 7.0
Local
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-41092
HIGH 7.8
Local
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-40409
HIGH 7.8
Local
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-40404
HIGH 7.8
Local
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability |
|
CVE-2026-34335
HIGH 7.0
Local
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-33828
HIGH 7.8
Local
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
|
CVE-2025-10263
CRITICAL 9.1
Réseau
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C… |
|
CVE-2026-48112
MEDIUM 6.5
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A … |
|
CVE-2026-48111
MEDIUM 4.3
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedenc… |
|
CVE-2026-48104
MEDIUM 4.2
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused b… |
|
CVE-2026-48103
MEDIUM 4.3
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) … |
|
CVE-2026-48102
LOW 3.1
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image ha… |
|
CVE-2026-48101
MEDIUM 6.5
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI cap… |
|
CVE-2026-48095
HIGH 8.8
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in … |
|
CVE-2026-48092
MEDIUM 4.3
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overf… |
|
CVE-2026-45585
MEDIUM 6.8
Physique
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerabi… |
|
CVE-2026-8975
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume th… |
|
CVE-2026-8974
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effor… |
|
CVE-2026-8973
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h… |
|
CVE-2026-8972
HIGH 8.8
Réseau 1 apps
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8971
MEDIUM 6.5
Réseau 1 apps
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8970
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8969
HIGH 8.1
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8968
HIGH 7.5
Réseau 1 apps
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird… |
|
CVE-2026-8967
HIGH 7.5
Réseau 1 apps
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8966
HIGH 7.5
Réseau 1 apps
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8965
HIGH 7.5
Réseau 1 apps
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8964
HIGH 7.5
Réseau 1 apps
Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8963
HIGH 7.5
Réseau 1 apps
Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8962
HIGH 8.1
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8961
MEDIUM 6.5
Réseau 1 apps
Spoofing issue in the Form Autofill component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8960
HIGH 7.5
Réseau 1 apps
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8959
HIGH 9.6
Réseau 1 apps
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbir… |
|
CVE-2026-8958
HIGH 8.6
Réseau 1 apps
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderb… |
|
CVE-2026-8957
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 14… |
|
CVE-2026-8956
HIGH 9.8
Réseau 1 apps
Integer overflow in the Networking: JAR component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8955
HIGH 8.8
Réseau 1 apps
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8954
HIGH 7.5
Réseau 1 apps
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151,… |
|
CVE-2026-8953
HIGH 9.6
Réseau 1 apps
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.… |
|
CVE-2026-8952
HIGH 8.8
Réseau 1 apps
Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8950
HIGH 9.3
Réseau 1 apps
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird … |
|
CVE-2026-8949
HIGH 7.5
Réseau 1 apps
Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11. |
|
CVE-2026-8948
CRITICAL 9.1
Réseau 1 apps
Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
|
CVE-2026-8947
HIGH 7.3
Réseau 1 apps
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, a… |
|
CVE-2026-8946
HIGH 7.5
Réseau 1 apps
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Th… |
|
CVE-2025-54518
HIGH 7.0
Local
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a dif… |
|
CVE-2026-41088
HIGH 7.8
Local
Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privile… |