Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 310 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2023-51385
MEDIUM 6.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-27885
MEDIUM 6.3 Local

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app ma…

CVE-2024-27850
MEDIUM 6.5 Réseau

This issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, v…

CVE-2024-27844
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, macOS Sonoma 14.5, visionOS 1.2. A website's permission dialog may persist af…

CVE-2024-27840
MEDIUM 6.3 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, ma…

CVE-2024-27838
MEDIUM 6.5 Réseau

The issue was addressed by adding additional logic. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14…

CVE-2024-27830
MEDIUM 6.5 Réseau

This issue was addressed through improved state management. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionO…

CVE-2024-27807
MEDIUM 4.3 Réseau

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5. An app may be able to circumvent A…

CVE-2024-27806
MEDIUM 5.5 Local

This issue was addressed with improved environment sanitization. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey …

CVE-2024-27805
MEDIUM 5.5 Local

An issue was addressed with improved validation of environment variables. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS …

CVE-2024-27800
MEDIUM 6.5 Réseau

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5,…

CVE-2024-23282
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A…

CVE-2024-23251
MEDIUM 4.6 Physique

An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sono…

CVE-2024-27792
MEDIUM 5.5 Local

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive…

CVE-2023-40389
MEDIUM 5.5 Local

The issue was addressed with improved restriction of data container access. This issue is fixed in macOS Ventura 13.6.5, macOS Monterey 12.7.4. An app may be a…

CVE-2024-4769
MEDIUM 5.9 Réseau 1 apps

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses…

CVE-2024-4768
MEDIUM 6.1 Réseau 1 apps

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi…

CVE-2024-4767
MEDIUM 4.3 Réseau 1 apps

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa…

CVE-2024-27852
MEDIUM 6.5 Réseau

A privacy issue was addressed with improved client ID handling for alternative app marketplaces. This issue is fixed in iOS 17.5 and iPadOS 17.5. A maliciously…

CVE-2024-27847
MEDIUM 5.5 Local

This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sono…

CVE-2024-27841
MEDIUM 5.5 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kerne…

CVE-2024-27834
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tv…

CVE-2024-27827
MEDIUM 5.5 Local

This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to read arbitrar…

CVE-2024-27821
MEDIUM 4.7 Local

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, watchOS 10.5. A shortcut may …

CVE-2024-27816
MEDIUM 5.5 Local

A logic issue was addressed with improved checks. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker may …

CVE-2024-27810
MEDIUM 5.5 Local

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS …

CVE-2024-27804
MEDIUM 5.5 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, visionOS 1.3, watchOS 10.…

CVE-2024-27789
MEDIUM 5.5 Local

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura …

CVE-2024-23236
MEDIUM 5.5 Local

A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to read arbitrary files.

CVE-2024-23229
MEDIUM 5.5 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, macOS Ventura 13.6.…

CVE-2024-30050
MEDIUM 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-23271
MEDIUM 6.5 Réseau

A logic issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. A m…

CVE-2024-3861
MEDIUM 4.0 Local 1 apps

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability…

CVE-2024-3859
MEDIUM 5.9 Réseau 1 apps

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulner…

CVE-2024-27247
MEDIUM 5.5 Local 1 apps

Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of…

CVE-2024-24694
MEDIUM 5.9 Local 1 apps

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalat…

CVE-2024-30370
MEDIUM 4.3 Réseau 1 apps

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i…

CVE-2023-42893
MEDIUM 5.5 Local

A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3,…

CVE-2024-1580
MEDIUM 5.9

[Apple CoreMedia] Processing an image may lead to arbitrary code execution

CVE-2024-26196
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability

CVE-2024-2611
MEDIUM 5.5 Réseau 1 apps

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox…

CVE-2024-2610
MEDIUM 6.1 Réseau 1 apps

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a…

CVE-2024-2609
MEDIUM 6.1 Réseau 1 apps

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi…

CVE-2024-2605
MEDIUM 5.9 Réseau 1 apps

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows …

CVE-2023-5388
MEDIUM 6.5 Réseau 1 apps

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data…

CVE-2024-23298
MEDIUM 5.5 Local 1 apps

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVE-2024-23297
MEDIUM 5.5 Local

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to …

CVE-2024-23293
MEDIUM 4.6 Physique

This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An att…

CVE-2024-23290
MEDIUM 5.5 Local

A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may…

CVE-2024-23287
MEDIUM 5.5 Local

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An a…