Vulnérabilités
Vulnérabilités des apps suivies
2 321 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-26196
MEDIUM 4.3
Réseau 1 apps
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability |
|
CVE-2024-2611
MEDIUM 5.5
Réseau 1 apps
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox… |
|
CVE-2024-2610
MEDIUM 6.1
Réseau 1 apps
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a… |
|
CVE-2024-2609
MEDIUM 6.1
Réseau 1 apps
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi… |
|
CVE-2024-2605
MEDIUM 5.9
Réseau 1 apps
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows … |
|
CVE-2023-5388
MEDIUM 6.5
Réseau 1 apps
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data… |
|
CVE-2024-23298
MEDIUM 5.5
Local 1 apps
A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks. |
|
CVE-2024-23297
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4. A malicious application may be able to … |
|
CVE-2024-23293
MEDIUM 4.6
Physique
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An att… |
|
CVE-2024-23290
MEDIUM 5.5
Local
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An app may… |
|
CVE-2024-23287
MEDIUM 5.5
Local
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. An a… |
|
CVE-2024-23285
MEDIUM 5.5
Local
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sonoma 14.4. An app may be able to create symlinks to protected regio… |
|
CVE-2024-23284
MEDIUM 6.5
Réseau
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS S… |
|
CVE-2024-23283
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4,… |
|
CVE-2024-23281
MEDIUM 5.5
Local
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4. An app may be able to access sensitive user data. |
|
CVE-2024-23280
MEDIUM 6.5
Réseau
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS … |
|
CVE-2024-23279
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user… |
|
CVE-2024-23277
MEDIUM 5.9
Réseau
The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An attacker in a privileged network position … |
|
CVE-2024-23275
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be… |
|
CVE-2024-23273
MEDIUM 4.3
Réseau
This issue was addressed through improved state management. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Private Browsing t… |
|
CVE-2024-23272
MEDIUM 5.5
Local
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An attacker may gain a… |
|
CVE-2024-23269
MEDIUM 5.5
Local
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Monterey 12.7.4, ma… |
|
CVE-2024-23267
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypa… |
|
CVE-2024-23266
MEDIUM 5.5
Local
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modi… |
|
CVE-2024-23264
MEDIUM 5.5
Local
A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Montere… |
|
CVE-2024-23263
MEDIUM 6.5
Réseau
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma … |
|
CVE-2024-23260
MEDIUM 5.5
Local
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Sonoma 14.4. An app may be able to access user-sensitive data. |
|
CVE-2024-23259
MEDIUM 6.5
Réseau
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Processing web … |
|
CVE-2024-23254
MEDIUM 6.5
Réseau
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, wa… |
|
CVE-2024-23250
MEDIUM 5.5
Local
An access issue was addressed with improved access restrictions. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A… |
|
CVE-2024-23241
MEDIUM 5.5
Local
This issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. An app may be able t… |
|
CVE-2024-23239
MEDIUM 4.7
Local
A race condition was addressed with improved state handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. An ap… |
|
CVE-2024-23235
MEDIUM 4.7
Local
A race condition was addressed with additional validation. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tv… |
|
CVE-2024-23234
MEDIUM 6.7
Local
An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.… |
|
CVE-2024-23231
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17… |
|
CVE-2024-23230
MEDIUM 5.5
Local
This issue was addressed with improved file handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able… |
|
CVE-2024-23220
MEDIUM 5.5
Local
The issue was addressed with improved handling of caches. This issue is fixed in iOS 17.4 and iPadOS 17.4, visionOS 1.1. An app may be able to fingerprint the … |
|
CVE-2024-23205
MEDIUM 5.5
Local
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app … |
|
CVE-2024-23201
MEDIUM 5.5
Local
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Monterey 12.7.4, macOS Sonoma 14.3, macO… |
|
CVE-2023-28826
MEDIUM 5.5
Local
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS So… |
|
CVE-2024-26167
MEDIUM 4.3
Réseau 1 apps
Microsoft Edge for Android Spoofing Vulnerability |
|
CVE-2024-26188
MEDIUM 4.3
Réseau 1 apps
Microsoft Edge (Chromium-based) Spoofing Vulnerability |
|
CVE-2023-42853
MEDIUM 5.5
Local
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS Monterey 12.7.1, macOS Ventura 13.6.1. An app may be able to … |
|
CVE-2024-1551
MEDIUM 6.1
Réseau 1 apps
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well … |
|
CVE-2024-1550
MEDIUM 6.1
Réseau 1 apps
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl… |
|
CVE-2024-1549
MEDIUM 6.1
Réseau 1 apps
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un… |
|
CVE-2024-1548
MEDIUM 4.3
Réseau 1 apps
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing… |
|
CVE-2024-1547
MEDIUM 6.5
Réseau 1 apps
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh… |
|
CVE-2024-24699
MEDIUM 6.5
Réseau 4 apps
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
MEDIUM 4.9
Réseau 4 apps
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |