Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2023-39199
MEDIUM 4.9 Réseau 4 apps

Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access.

CVE-2023-36029
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge (Chromium-based) Spoofing Vulnerability

CVE-2023-42861
MEDIUM 6.5 Réseau

A logic issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.1. An attacker with knowledge of a standard user's credentia…

CVE-2023-5732
MEDIUM 6.5 Réseau 1 apps

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affect…

CVE-2023-5727
MEDIUM 6.5 Réseau 1 apps

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. …

CVE-2023-5726
MEDIUM 4.3 Réseau 1 apps

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. …

CVE-2023-5725
MEDIUM 4.3 Réseau 1 apps

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner…

CVE-2023-5721
MEDIUM 4.3 Réseau 1 apps

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This …

CVE-2023-5171
MEDIUM 6.5 Réseau 1 apps

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent…

CVE-2023-5169
MEDIUM 6.5 Réseau 1 apps

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable…

CVE-2023-40435
MEDIUM 5.5 Local 1 apps

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.

CVE-2022-20917
MEDIUM 4.3 Réseau 2 apps

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack…

CVE-2023-4581
MEDIUM 4.3 Réseau 1 apps

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot…

CVE-2023-4580
MEDIUM 6.5 Réseau 1 apps

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability …

CVE-2023-4578
MEDIUM 6.5 Réseau 1 apps

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul…

CVE-2023-4577
MEDIUM 6.5 Réseau 1 apps

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot…

CVE-2023-4575
MEDIUM 6.5 Réseau 1 apps

When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul…

CVE-2023-4574
MEDIUM 6.5 Réseau 1 apps

When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu…

CVE-2023-4573
MEDIUM 6.5 Réseau 1 apps

When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp…

CVE-2022-32920
MEDIUM 5.5 Local 1 apps

The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information.

CVE-2023-40217
MEDIUM 5.3 Réseau 1 apps

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT…

CVE-2022-48566
MEDIUM 5.9 Réseau 1 apps

An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab…

CVE-2022-48564
MEDIUM 6.5 Réseau 1 apps

read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li…

CVE-2023-38898
MEDIUM 5.3 Réseau 1 apps

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th…

CVE-2023-39209
MEDIUM 5.9 Réseau 1 apps

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network acce…

CVE-2023-39218
MEDIUM 6.1 Réseau 4 apps

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access.

CVE-2023-38254
MEDIUM 6.5 Réseau

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36914
MEDIUM 5.5 Local

Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability

CVE-2023-36913
MEDIUM 6.5 Réseau

Microsoft Message Queuing Information Disclosure Vulnerability

CVE-2023-36909
MEDIUM 6.5 Réseau

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36908
MEDIUM 6.5 Réseau adjacent

Windows Hyper-V Information Disclosure Vulnerability

CVE-2023-36907
MEDIUM 5.5 Local

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36906
MEDIUM 5.5 Local

Windows Cryptographic Services Information Disclosure Vulnerability

CVE-2023-36905
MEDIUM 5.5 Local

Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability

CVE-2023-36889
MEDIUM 5.5 Local

Windows Group Policy Security Feature Bypass Vulnerability

CVE-2023-36532
MEDIUM 5.9 Réseau 4 apps

Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access.

CVE-2023-35384
MEDIUM 5.4 Réseau

Windows HTML Platforms Security Feature Bypass Vulnerability

CVE-2023-35377
MEDIUM 6.5 Réseau

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-35376
MEDIUM 6.5 Réseau

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

CVE-2023-36883
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge for iOS Spoofing Vulnerability

CVE-2023-37207
MEDIUM 6.5 Réseau 1 apps

A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have le…

CVE-2023-26083
MEDIUM KEV

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-25012
MEDIUM 4.6

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-42703
MEDIUM 5.5

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-36539
MEDIUM 5.3 Réseau 4 apps

Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information.

CVE-2023-34658
MEDIUM 5.3 Réseau 1 apps

Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.

CVE-2023-32395
MEDIUM 5.5 Local

A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may …

CVE-2023-29545
MEDIUM 6.5 Réseau 1 apps

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c…

CVE-2023-29532
MEDIUM 5.5 Local 1 apps

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s…

CVE-2023-34121
MEDIUM 4.1 Réseau 1 apps

Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially…