Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

545 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-39891
MEDIUM 5.3 KEV Réseau 2 apps

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb…

CVE-2024-34130
MEDIUM 5.5 Local 1 apps

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature …

CVE-2024-26196
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

CVE-2024-26167
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge for Android Spoofing Vulnerability

CVE-2024-26188
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2024-24699
MEDIUM 6.5 Réseau 4 apps

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24698
MEDIUM 4.9 Réseau 4 apps

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-24690
MEDIUM 5.4 Réseau 4 apps

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-49646
MEDIUM 6.4 Réseau 4 apps

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43583
MEDIUM 4.9 Réseau 2 apps

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user …

CVE-2023-45866
MEDIUM 6.3

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-43582
MEDIUM 5.5 Réseau 4 apps

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-39205
MEDIUM 4.3 Réseau 4 apps

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39204
MEDIUM 4.3 Réseau 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39199
MEDIUM 4.9 Réseau 4 apps

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2023-36029
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2022-20917
MEDIUM 4.3 Réseau 2 apps

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack…

CVE-2023-39218
MEDIUM 6.1 Réseau 4 apps

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-36532
MEDIUM 5.9 Réseau 4 apps

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-26083
MEDIUM KEV

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-25012
MEDIUM 4.6

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-42703
MEDIUM 5.5

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-36539
MEDIUM 5.3 Réseau 4 apps

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-28599
MEDIUM 4.3 Réseau 4 apps

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-29548
MEDIUM 6.5 Réseau 1 apps

A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 1…

CVE-2023-29544
MEDIUM 6.5 Réseau 1 apps

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploi…

CVE-2023-29535
MEDIUM 6.5 Réseau 1 apps

Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentia…

CVE-2023-29533
MEDIUM 4.3 Réseau 1 apps

A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> ass…

CVE-2023-21116
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-28284
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2023-20950
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-24923
MEDIUM 5.5 Local 1 apps

Microsoft OneDrive for Android Information Disclosure Vulnerability

CVE-2021-29647
MEDIUM 5.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2021-33655
MEDIUM 6.7

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-21721
MEDIUM 6.5 Réseau 1 apps

Microsoft OneNote Elevation of Privilege Vulnerability

CVE-2022-39842
MEDIUM 6.1

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-36928
MEDIUM 6.1 Local 1 apps

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to …

CVE-2022-42721
MEDIUM 5.5

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-16135
MEDIUM 6.5 Réseau 1 apps

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVE-2022-24480
MEDIUM 6.3 Physique 1 apps

Outlook for Android Elevation of Privilege Vulnerability

CVE-2022-43363
MEDIUM 6.1 Réseau 2 apps

Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati…

CVE-2022-20468
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20466
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20454
MEDIUM 6.7

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20415
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20412
MEDIUM 6.7

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20409
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-39758
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20197
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-32550
MEDIUM 4.8 Réseau 4 apps

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic…