Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 302 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-11708
MEDIUM 6.5 Réseau 1 apps

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an…

CVE-2024-11706
MEDIUM 6.5 Réseau 1 apps

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed o…

CVE-2024-11701
MEDIUM 4.3 Réseau 1 apps

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible sp…

CVE-2024-11696
MEDIUM 5.4 Réseau 1 apps

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an i…

CVE-2024-11695
MEDIUM 5.4 Réseau 1 apps

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This …

CVE-2024-11694
MEDIUM 6.1 Réseau 1 apps

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the W…

CVE-2024-11692
MEDIUM 4.3 Réseau 1 apps

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability…

CVE-2024-11612
MEDIUM 6.5 Réseau 1 apps

7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected i…

CVE-2024-44309
MEDIUM 6.3 KEV Réseau

A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPad…

CVE-2024-11159
MEDIUM 4.3 Réseau 1 apps

Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < …

CVE-2024-24795
MEDIUM 6.3

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-2379
MEDIUM 6.3

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2023-48795
MEDIUM 5.9

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-44234
MEDIUM 5.5 Local

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS S…

CVE-2024-44233
MEDIUM 5.5 Local

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS S…

CVE-2024-44232
MEDIUM 5.5 Local

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS S…

CVE-2024-10468
MEDIUM 5.3 Réseau 1 apps

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13…

CVE-2024-10465
MEDIUM 6.5 Réseau 1 apps

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir…

CVE-2024-10464
MEDIUM 6.5 Réseau 1 apps

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r…

CVE-2024-10463
MEDIUM 6.5 Réseau 1 apps

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th…

CVE-2024-10462
MEDIUM 6.5 Réseau 1 apps

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird …

CVE-2024-10461
MEDIUM 6.1 Réseau 1 apps

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could al…

CVE-2024-10460
MEDIUM 5.3 Réseau 1 apps

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Fire…

CVE-2024-44295
MEDIUM 5.5 Local

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An app may b…

CVE-2024-44283
MEDIUM 5.5 Local

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsin…

CVE-2024-44260
MEDIUM 4.4 Local

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious app…

CVE-2024-44257
MEDIUM 5.5 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1…

CVE-2024-44240
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 1…

CVE-2024-44237
MEDIUM 5.5 Local

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1…

CVE-2024-44216
MEDIUM 5.5 Local

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. An ap…

CVE-2024-44145
MEDIUM 6.1 Physique

This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15. An attacker with physical access to …

CVE-2024-44302
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 1…

CVE-2024-44301
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may…

CVE-2024-44297
MEDIUM 6.5 Réseau

The issue was addressed with improved bounds checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS S…

CVE-2024-44296
MEDIUM 5.4 Réseau

The issue was addressed with improved checks. This issue is fixed in Safari 18.1, iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, t…

CVE-2024-44294
MEDIUM 6.5 Réseau

A path deletion vulnerability was addressed by preventing vulnerable code from running with privileges. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma…

CVE-2024-44287
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may…

CVE-2024-44284
MEDIUM 5.5 Local

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1…

CVE-2024-44282
MEDIUM 5.5 Local

An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoi…

CVE-2024-44281
MEDIUM 5.5 Local

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsi…

CVE-2024-44280
MEDIUM 5.5 Local

A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.1, macOS…

CVE-2024-44279
MEDIUM 5.5 Local

An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. Parsi…

CVE-2024-44278
MEDIUM 5.5 Local

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18…

CVE-2024-44275
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may…

CVE-2024-44274
MEDIUM 4.6 Physique

The issue was addressed with improved authentication. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. An attacker …

CVE-2024-44273
MEDIUM 5.5 Local

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, tvOS 18.…

CVE-2024-44269
MEDIUM 5.5 Local

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.7.1 and iPadOS 17.7.1, iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sono…

CVE-2024-44267
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may…

CVE-2024-44264
MEDIUM 5.5 Local

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A maliciou…

CVE-2024-44263
MEDIUM 5.5 Local

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access user-sensitive data.