Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

1,040 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2024-23210
LOW 3.3 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watch…

CVE-2024-23208
HIGH 7.8 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may …

CVE-2024-23207
MEDIUM 5.5 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.3, macOS Sonoma…

CVE-2024-23206
MEDIUM 6.5 Network

An access issue was addressed with improved access restrictions. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, ma…

CVE-2024-23204
HIGH 7.5 Network

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.…

CVE-2024-23203
HIGH 7.5 Network

The issue was addressed with additional permissions checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, m…

CVE-2023-42937
MEDIUM 5.5 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ve…

CVE-2023-42888
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.5 and iPadOS 16.7.5, watchOS 10.2, macOS Ventura 13.6.4, macOS Sonoma 14.2, macOS…

CVE-2023-41974
HIGH 7.8 KEV Local

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be …

CVE-2023-49646
MEDIUM 6.4 Network 4 apps

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43585
HIGH 7.1 Network 1 apps

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of infor…

CVE-2023-43583
MEDIUM 4.9 Network 2 apps

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user …

CVE-2023-42917
HIGH 8.8 KEV Network

A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2.…

CVE-2023-42916
MEDIUM 6.5 KEV Network

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Pr…

CVE-2023-43582
MEDIUM 5.5 Network 4 apps

Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

CVE-2023-39206
LOW 3.7 Network 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39205
MEDIUM 4.3 Network 4 apps

Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39204
MEDIUM 4.3 Network 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-39199
MEDIUM 4.9 Network 4 apps

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2022-20917
MEDIUM 4.3 Network 2 apps

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack…

CVE-2023-39215
HIGH 7.1 Network 4 apps

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-39214
HIGH 7.6 Network 4 apps

Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access.

CVE-2023-39218
MEDIUM 6.1 Network 4 apps

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-36535
HIGH 7.1 Network 4 apps

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network acc…

CVE-2023-36532
MEDIUM 5.9 Network 4 apps

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-29330
HIGH 8.8 Network 1 apps

Microsoft Teams Remote Code Execution Vulnerability

CVE-2023-29328
HIGH 8.8 Network 1 apps

Microsoft Teams Remote Code Execution Vulnerability

CVE-2023-36883
MEDIUM 4.3 Network 1 apps

Microsoft Edge for iOS Spoofing Vulnerability

CVE-2023-36539
MEDIUM 5.3 Network 4 apps

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-34658
MEDIUM 5.3 Network 1 apps

Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.

CVE-2023-28599
MEDIUM 4.3 Network 4 apps

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-28597
HIGH 8.3 Adjacent network 4 apps

Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later …

CVE-2023-24890
MEDIUM 6.5 Network 1 apps

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

CVE-2022-44708
HIGH 8.3 Network 1 apps

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

CVE-2022-43363
MEDIUM 6.1 Network 2 apps

Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati…

CVE-2022-27492
HIGH 7.8 Local 2 apps

An integer underflow in WhatsApp could have caused remote code execution when receiving a crafted video file.

CVE-2022-36934
CRITICAL 9.8 Network 2 apps

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-28755
CRITICAL 9.6 Network 2 apps

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious…

CVE-2022-32550
MEDIUM 4.8 Network 4 apps

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic…

CVE-2021-44683
HIGH 8.2 Network 1 apps

The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open function (used to open a secondary browser wi…

CVE-2020-20096
MEDIUM 6.5 Network 2 apps

Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofin…

CVE-2022-21965
HIGH 7.5 Network 2 apps

Microsoft Teams Denial of Service Vulnerability

CVE-2021-24043
CRITICAL 9.1 Network 2 apps

A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.…

CVE-2021-24042
CRITICAL 9.8 Network 2 apps

The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Bu…

CVE-2021-36769
MEDIUM 5.3 Network 2 apps

A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the ser…

CVE-2021-31323
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty fu…

CVE-2021-31322
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of thei…

CVE-2021-31321
HIGH 7.1 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their cus…

CVE-2021-31320
HIGH 7.1 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorT…

CVE-2021-31319
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their c…