Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

11 325 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-20928
HIGH 4.6

Windows Recovery Environment Security Feature Bypass Vulnerability

CVE-2026-20806
HIGH 5.5

Windows COM Server Information Disclosure Vulnerability

CVE-2026-0390
HIGH 6.7

UEFI Secure Boot Security Feature Bypass Vulnerability

CVE-2023-20585
HIGH 5.3

AMD: CVE-2023-20585 IOMMU Write Buffer Vulnerability

CVE-2026-20432
HIGH 8.0 Réseau adjacent

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a …

CVE-2025-43264
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me…

CVE-2025-43257
HIGH 8.7 Local

This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.6. An app may be able to break out of its sandbox.

CVE-2025-43219
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6. Processing a maliciously crafted image may corrupt process me…

CVE-2025-43202
HIGH 8.8 Réseau

This issue was addressed with improved memory handling. This issue is fixed in iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6. Processing a file may lead to memo…

CVE-2024-44303
HIGH 7.5 Réseau

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1. A malicious application may be able to modify protected parts of the f…

CVE-2024-44286
HIGH 7.5 Réseau

This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access can input keyboard even…

CVE-2024-44250
HIGH 8.2 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to execute arbitrary code out of …

CVE-2024-44219
HIGH 7.5 Réseau

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. A malicious application with root privileges may be …

CVE-2024-40858
HIGH 7.1 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.1. An app may be able to access Contacts without user c…

CVE-2024-40849
HIGH 7.5 Réseau

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.1. An app may be able to break out of its sandbox.

CVE-2026-28894
HIGH 7.5 Réseau

A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.…

CVE-2026-28891
HIGH 8.1 Local

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app may be ab…

CVE-2026-28876
HIGH 7.5 Réseau

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 a…

CVE-2026-28875
HIGH 7.5 Réseau

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denial…

CVE-2026-28874
HIGH 7.5 Réseau

The issue was addressed with improved checks. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote attacker may cause an unexpected app termination.

CVE-2026-28865
HIGH 7.5 Réseau

An authentication issue was addressed with improved state management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ…

CVE-2026-28855
HIGH 7.5 Réseau

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Tahoe 26.3. An app may be able to access…

CVE-2026-28842
HIGH 7.5 Réseau

The issue was addressed with improved bounds checks. This issue is fixed in macOS Tahoe 26.4. A buffer overflow may result in memory corruption and unexpected …

CVE-2026-28837
HIGH 7.5 Réseau

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

CVE-2026-28832
HIGH 8.4 Local

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app m…

CVE-2026-28825
HIGH 7.1 Réseau

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A…

CVE-2026-28821
HIGH 8.4 Local

A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed i…

CVE-2026-28817
HIGH 8.1 Local

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. A sandboxed pr…

CVE-2026-20701
HIGH 7.5 Réseau

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4. An app …

CVE-2026-20698
HIGH 7.8 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Tahoe 26.4, tvOS 26.4, visionOS 26.4, watchOS 26.…

CVE-2026-20687
HIGH 7.1 Local

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequ…

CVE-2026-20639
HIGH 7.5 Réseau

An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.3. Processin…

CVE-2026-20631
HIGH 8.8 Réseau

A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. A user may be able to elevate privileges.

CVE-2026-20622
HIGH 7.5 Réseau

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.3. An app may be able to c…

CVE-2026-4371
HIGH 7.4 Réseau 1 apps

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connectio…

CVE-2026-4727
HIGH 7.5 Réseau 1 apps

Denial-of-service in the Libraries component in NSS. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4726
HIGH 7.5 Réseau 1 apps

Denial-of-service in the XML component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

CVE-2026-4718
HIGH 8.1 Réseau 1 apps

Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

CVE-2026-4694
HIGH 7.5 Réseau 1 apps

Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, …

CVE-2025-59775
HIGH 7.5

[Apple apache] Multiple issues in Apache

CVE-2025-58098
HIGH 8.3

[Apple apache] Multiple issues in Apache

CVE-2026-4424
HIGH 7.5 Réseau

A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sl…

CVE-2026-4224
HIGH 7.5 Réseau 1 apps

When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply nested content model a C stack overflow…

CVE-2026-3644
HIGH 7.5 Réseau 1 apps

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths wer…

CVE-2026-26133
HIGH 7.1 Réseau 13 apps

AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2023-43010
HIGH 8.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15 and iPadOS …

CVE-2026-26134
HIGH 7.8 Local 1 apps

Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

CVE-2026-25180
HIGH 5.5 Local 1 apps

Out-of-bounds read in Microsoft Graphics Component allows an unauthorized attacker to disclose information locally.

CVE-2026-24294
HIGH 7.8 Local

Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

CVE-2026-24293
HIGH 7.8 Local

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.