Vulnérabilités
Vulnérabilités des apps suivies
1 040 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-31318
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function … |
|
CVE-2021-31317
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of … |
|
CVE-2021-31315
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of … |
|
CVE-2021-21211
MEDIUM 6.5
Réseau 1 apps
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML… |
|
CVE-2021-21205
HIGH 8.1
Réseau 1 apps
Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a c… |
|
CVE-2021-30496
MEDIUM 5.7
Réseau 1 apps
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied mes… |
|
CVE-2021-24026
CRITICAL 9.8
Réseau 2 apps
A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v… |
|
CVE-2021-24114
MEDIUM 5.7
Réseau 1 apps
Microsoft Teams iOS Information Disclosure Vulnerability |
|
CVE-2021-27205
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure. |
|
CVE-2021-27204
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. |
|
CVE-2020-1909
CRITICAL 9.8
Réseau 1 apps
A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory cor… |
|
CVE-2020-1908
MEDIUM 4.6
Physique 1 apps
Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact wit… |
|
CVE-2020-1907
CRITICAL 9.8
Réseau 2 apps
A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsA… |
|
CVE-2020-1904
MEDIUM 5.5
Local 1 apps
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwr… |
|
CVE-2020-1903
MEDIUM 5.5
Local 1 apps
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulte… |
|
CVE-2020-1901
MEDIUM 5.3
Réseau 1 apps
Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message. |
|
CVE-2020-1894
HIGH 8.8
Réseau 2 apps
A stack write overflow in WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and W… |
|
CVE-2020-1891
CRITICAL 9.8
Réseau 2 apps
A user controlled parameter used in video call in WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone p… |
|
CVE-2020-15502
HIGH 7.5
Réseau 2 apps
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers… |
|
CVE-2020-12474
MEDIUM 6.5
Réseau 2 apps
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public U… |
|
CVE-2019-18426
HIGH 8.2
KEV
Réseau 1 apps
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.20.10 allows cross-site scripting and l… |
|
CVE-2019-11931
HIGH 7.8
Local 2 apps
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the e… |
|
CVE-2019-11927
HIGH 7.8
Local 2 apps
An integer overflow in WhatsApp media parsing libraries allows a remote attacker to perform an out-of-bounds write on the heap via specially-crafted EXIF tags … |
|
CVE-2019-14319
MEDIUM 6.5
Réseau adjacent 2 apps
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker… |
|
CVE-2019-15514
MEDIUM 5.3
Réseau 2 apps
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attac… |
|
CVE-2019-1948
MEDIUM 5.9
Réseau 1 apps
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by usin… |
|
CVE-2019-1218
MEDIUM 5.4
Réseau 1 apps
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit t… |
|
CVE-2019-1084
MEDIUM 6.5
Réseau 2 apps
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated a… |
|
CVE-2018-20655
CRITICAL 9.8
Réseau 1 apps
When receiving calls using WhatsApp for iOS, a missing size check when parsing a sender-provided packet allowed for a stack-based overflow. This issue affects … |
|
CVE-2019-10044
HIGH 8.8
Réseau 2 apps
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying … |
|
CVE-2018-6976
MEDIUM 5.3
Réseau 1 apps
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted file… |
|
CVE-2018-12271
MEDIUM 6.4
Physique 1 apps
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by… |
|
CVE-2017-17689
MEDIUM 5.9
Réseau 3 apps
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. |
|
CVE-2018-1167
HIGH 8.8
Réseau 3 apps
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is requir… |
|
CVE-2018-6849
MEDIUM 4.3
Réseau 2 apps
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), th… |
|
CVE-2016-10511
MEDIUM 5.9
Réseau 1 apps
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitti… |
|
CVE-2016-4075
MEDIUM 6.1
Réseau 2 apps
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL. |
|
CVE-2017-2391
MEDIUM 5.3
Réseau 9 apps
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3… |
|
CVE-2012-6399
N/A
1 apps
Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 ce… |
|
CVE-2012-6140
N/A
2 apps
pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local user… |