Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

1 821 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2018-5159
CRITICAL 9.8 Réseau 1 apps

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds wr…

CVE-2018-5155
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vu…

CVE-2018-5154
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. T…

CVE-2018-5150
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume …

CVE-2018-5146
CRITICAL 8.8 Réseau 1 apps

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox…

CVE-2018-5145
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these…

CVE-2018-5104
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable cra…

CVE-2018-5103
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. …

CVE-2018-5102
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerabi…

CVE-2018-5099
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in…

CVE-2018-5098
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially explo…

CVE-2018-5097
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the…

CVE-2018-5096
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affe…

CVE-2018-5095
CRITICAL 9.8 Réseau 1 apps

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the u…

CVE-2018-5089
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7828
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a…

CVE-2017-7826
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7824
CRITICAL 9.8 Réseau 1 apps

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being …

CVE-2017-7819
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. T…

CVE-2017-7818
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. T…

CVE-2017-7810
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7809
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results i…

CVE-2017-7802
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack…

CVE-2017-7801
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while…

CVE-2017-7800
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This res…

CVE-2017-7793
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially expl…

CVE-2017-7792
CRITICAL 9.8 Réseau 1 apps

A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This resul…

CVE-2017-7786
CRITICAL 9.8 Réseau 1 apps

A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulne…

CVE-2017-7785
CRITICAL 9.8 Réseau 1 apps

A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable…

CVE-2017-7784
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potent…

CVE-2017-7779
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume …

CVE-2017-7778
CRITICAL 9.8 Réseau 1 apps

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized me…

CVE-2017-7758
CRITICAL 9.1 Réseau 1 apps

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerabilit…

CVE-2017-7757
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a pote…

CVE-2017-7756
CRITICAL 9.8 Réseau 1 apps

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable…

CVE-2017-7753
CRITICAL 9.1 Réseau 1 apps

An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbir…

CVE-2017-7751
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox …

CVE-2017-7750
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced i…

CVE-2017-7749
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerabil…

CVE-2017-5472
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no …

CVE-2017-5470
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-5469
CRITICAL 9.8 Réseau 1 apps

Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.…

CVE-2017-5465
CRITICAL 9.1 Réseau 1 apps

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i…

CVE-2017-5464
CRITICAL 9.8 Réseau 1 apps

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruptio…

CVE-2017-5460
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potential…

CVE-2017-5459
CRITICAL 9.8 Réseau 1 apps

A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR…

CVE-2017-5447
CRITICAL 9.1 Réseau 1 apps

An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to …

CVE-2017-5446
CRITICAL 9.8 Réseau 1 apps

An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. Th…

CVE-2017-5443
CRITICAL 9.8 Réseau 1 apps

An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9…

CVE-2017-5442
CRITICAL 9.8 Réseau 1 apps

A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affe…