Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 303 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-40777
MEDIUM 5.5 Local

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visio…

CVE-2024-40776
MEDIUM 4.3 Réseau

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 17.6, iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.…

CVE-2024-40775
MEDIUM 5.5 Local

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.…

CVE-2024-27888
MEDIUM 5.5 Local

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sonoma 14.4. An app may be able to mod…

CVE-2024-27887
MEDIUM 5.5 Local

A path handling issue was addressed with improved validation. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data.

CVE-2024-27886
MEDIUM 5.5 Local

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.4, macOS Ventura 13.7. An unprivileged app may be able to log ke…

CVE-2024-27884
MEDIUM 5.5 Local

This issue was addressed with a new entitlement. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.2, watchOS 10.5. An …

CVE-2024-27883
MEDIUM 4.4 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m…

CVE-2024-27882
MEDIUM 4.4 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app m…

CVE-2024-27881
MEDIUM 5.3 Réseau

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Vent…

CVE-2024-27878
MEDIUM 6.7 Local

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.6. An app may be able to execute arbitrary code wit…

CVE-2024-27877
MEDIUM 6.1 Local

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Processing a mali…

CVE-2024-27873
MEDIUM 5.5 Local

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS…

CVE-2024-27872
MEDIUM 5.5 Local

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be able to access protected user data.

CVE-2024-27871
MEDIUM 5.5 Local

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app may be able to access …

CVE-2024-27863
MEDIUM 5.5 Local

An information disclosure issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sono…

CVE-2024-27853
MEDIUM 4.4 Local

This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.

CVE-2024-27823
MEDIUM 5.9 Réseau

A race condition was addressed with improved locking. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, mac…

CVE-2024-27809
MEDIUM 5.5 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user…

CVE-2024-6614
MEDIUM 4.3 Réseau 1 apps

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

CVE-2024-6613
MEDIUM 5.5 Local 1 apps

The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 …

CVE-2024-6612
MEDIUM 5.3 Réseau 1 apps

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CS…

CVE-2024-6610
MEDIUM 4.3 Réseau 1 apps

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen m…

CVE-2024-6608
MEDIUM 4.3 Réseau 1 apps

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulner…

CVE-2024-6603
MEDIUM 7.4 Réseau 1 apps

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerabilit…

CVE-2024-6601
MEDIUM 4.7 Réseau 1 apps

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < …

CVE-2024-6600
MEDIUM 6.3 Réseau 1 apps

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private s…

CVE-2024-39684
MEDIUM 7.8

Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability

CVE-2024-38517
MEDIUM 7.8

Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability

CVE-2024-39891
MEDIUM 5.3 KEV Réseau 2 apps

In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-numb…

CVE-2024-30057
MEDIUM 5.4 Réseau 1 apps

Microsoft Edge for iOS Spoofing Vulnerability

CVE-2024-34130
MEDIUM 5.5 Local 1 apps

Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature …

CVE-2024-30096
MEDIUM 5.5 Local

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2024-30076
MEDIUM 6.8 Réseau

Windows Container Manager Service Elevation of Privilege Vulnerability

CVE-2024-30069
MEDIUM 4.7 Local

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2024-30067
MEDIUM 5.5 Local

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30066
MEDIUM 5.5 Local

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30065
MEDIUM 5.5 Local

Windows Themes Denial of Service Vulnerability

CVE-2024-30063
MEDIUM 6.7 Réseau adjacent

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

CVE-2024-5693
MEDIUM 6.1 Réseau 1 apps

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T…

CVE-2024-5692
MEDIUM 6.5 Réseau 1 apps

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur…

CVE-2024-5691
MEDIUM 4.7 Réseau 1 apps

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions…

CVE-2024-5690
MEDIUM 4.3 Réseau 1 apps

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner…

CVE-2023-51385
MEDIUM 6.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-27885
MEDIUM 6.3 Local

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app ma…

CVE-2024-27850
MEDIUM 6.5 Réseau

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, v…

CVE-2024-27844
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist af…

CVE-2024-27840
MEDIUM 6.3 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, ma…

CVE-2024-27838
MEDIUM 6.5 Réseau

The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14…

CVE-2024-27830
MEDIUM 6.5 Réseau

This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionO…