Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

180 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-40791
LOW 3.3 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macO…

CVE-2024-40832
LOW 3.3 Local

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.

CVE-2024-40822
LOW 2.4 Physique

This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macO…

CVE-2024-40798
LOW 3.3 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS So…

CVE-2024-40795
LOW 3.3 Local

This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may…

CVE-2024-40778
LOW 3.3 Local

An authentication issue was addressed with improved state management. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Sono…

CVE-2024-27862
LOW 2.4 Physique

A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.6. Enabling Lockdown Mode while setting up a Mac may cause F…

CVE-2023-38546
LOW 3.7

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2024-27845
LOW 3.3 Local

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.5 and iPadOS 17.5. An app may be able to access Notes at…

CVE-2024-27819
LOW 2.4 Physique

The issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access ma…

CVE-2024-27799
LOW 3.3 Local

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 14.5, mac…

CVE-2024-32021
LOW 3.9 Local 1 apps

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that con…

CVE-2024-32020
LOW 3.9 Local 1 apps

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into …

CVE-2024-27839
LOW 3.3 Local

A privacy issue was addressed by moving sensitive data to a more secure location. This issue is fixed in iOS 17.5 and iPadOS 17.5. A malicious application may …

CVE-2024-27837
LOW 3.3 Local

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. A local attacker may gain access to Keycha…

CVE-2024-27835
LOW 2.4 Physique

This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access to an iOS device …

CVE-2024-27803
LOW 2.4 Physique

A permissions issue was addressed with improved validation. This issue is fixed in iOS 17.5 and iPadOS 17.5. An attacker with physical access may be able to sh…

CVE-2024-23228
LOW 3.3 Local

This issue was addressed through improved state management. This issue is fixed in iOS 17.3 and iPadOS 17.3. Locked Notes content may have been unexpectedly un…

CVE-2024-3302
LOW 3.7 Réseau 1 apps

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the b…

CVE-2024-2616
LOW 2.7 Réseau 1 apps

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F…

CVE-2024-26246
LOW 3.9 Physique 1 apps

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2024-23292
LOW 3.3 Local

This issue was addressed with improved data protection. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to access inform…

CVE-2024-23291
LOW 3.3 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17…

CVE-2024-23289
LOW 3.3 Local

A lock screen issue was addressed with improved state management. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 1…

CVE-2024-23262
LOW 3.3 Local

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, visionOS 1.1. An ap…

CVE-2024-23257
LOW 3.3 Local

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ven…

CVE-2024-23255
LOW 2.4 Physique

An authentication issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. Photos in the Hidden …

CVE-2024-23253
LOW 3.3 Local

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.

CVE-2024-23245
LOW 3.3 Local

This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5…

CVE-2024-23242
LOW 3.3 Local

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4. An app may be able to…

CVE-2024-23240
LOW 2.4 Physique

The issue was addressed with improved checks. This issue is fixed in iOS 17.4 and iPadOS 17.4. Shake-to-undo may allow a deleted photo to be re-surfaced withou…

CVE-2024-23238
LOW 3.3 Local

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to edit NVRAM variables.

CVE-2024-23232
LOW 3.3 Local

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capture a user's scree…

CVE-2024-23227
LOW 3.3 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.…

CVE-2024-23256
LOW 3.3 Local

A logic issue was addressed with improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4. A user's locked tabs may be briefly visible while …

CVE-2024-23243
LOW 3.3 Local

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4. An app may be able to read…

CVE-2024-23743
LOW 3.3 Local 2 apps

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must lau…

CVE-2024-23217
LOW 3.3 Local

A privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, macOS Ventura 13.6…

CVE-2024-23211
LOW 3.3 Local

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS…

CVE-2024-23210
LOW 3.3 Local

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watch…

CVE-2023-43588
LOW 3.5 Réseau 2 apps

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

CVE-2023-39206
LOW 3.7 Réseau 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-38039
LOW

Hackerone: CVE-2023-38039 HTTP headers eat all memory

CVE-2020-29374
LOW 3.6

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-34414
LOW 3.1 Réseau 1 apps

The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha…

CVE-2023-28602
LOW 2.8 Local 1 apps

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade…

CVE-2023-28301
LOW 3.7 Réseau 1 apps

Microsoft Edge (Chromium-based) Tampering Vulnerability

CVE-2022-36835
LOW 3.3 Local 1 apps

Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.

CVE-2021-3655
LOW 3.3

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-41861
LOW 3.3 Local 1 apps

The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. Aft…