Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

2,321 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2023-28600
MEDIUM 5.2 Local 1 apps

Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten…

CVE-2023-28599
MEDIUM 4.3 Network 4 apps

Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi…

CVE-2023-33595
MEDIUM 5.5 Local 1 apps

CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.

CVE-2023-32212
MEDIUM 4.3 Network 1 apps

An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb…

CVE-2023-32211
MEDIUM 6.5 Network 1 apps

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVE-2023-32206
MEDIUM 6.5 Network 1 apps

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102…

CVE-2023-32205
MEDIUM 4.3 Network 1 apps

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac…

CVE-2023-29548
MEDIUM 6.5 Network 1 apps

A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 1…

CVE-2023-29544
MEDIUM 6.5 Network 1 apps

If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploi…

CVE-2023-29535
MEDIUM 6.5 Network 1 apps

Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentia…

CVE-2023-29533
MEDIUM 4.3 Network 1 apps

A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> ass…

CVE-2023-28164
MEDIUM 6.5 Network 1 apps

Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af…

CVE-2023-28163
MEDIUM 6.5 Network 1 apps

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those …

CVE-2023-25752
MEDIUM 6.5 Network 1 apps

When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code…

CVE-2023-25751
MEDIUM 6.5 Network 1 apps

Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially …

CVE-2023-25742
MEDIUM 6.5 Network 1 apps

When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T…

CVE-2023-25738
MEDIUM 6.5 Network 1 apps

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo…

CVE-2023-25730
MEDIUM 5.4 Network 1 apps

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result…

CVE-2023-25728
MEDIUM 6.5 Network 1 apps

The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t…

CVE-2023-23603
MEDIUM 6.5 Network 1 apps

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Da…

CVE-2023-23602
MEDIUM 6.5 Network 1 apps

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to co…

CVE-2023-23601
MEDIUM 6.5 Network 1 apps

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability…

CVE-2023-23599
MEDIUM 6.5 Network 1 apps

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands …

CVE-2023-23598
MEDIUM 6.5 Network 1 apps

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website cou…

CVE-2023-1945
MEDIUM 6.5 Network 1 apps

Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunder…

CVE-2023-0616
MEDIUM 6.5 Network 1 apps

If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause T…

CVE-2023-0547
MEDIUM 6.5 Network 1 apps

OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. Thunderbird v…

CVE-2023-0430
MEDIUM 6.5 Network 1 apps

Certificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayed as having a vali…

CVE-2023-27952
MEDIUM 4.7 Local

A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.

CVE-2023-27945
MEDIUM 6.3 Local 1 apps

This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be abl…

CVE-2023-21116
MEDIUM

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-27043
MEDIUM 5.3 Network 1 apps

The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident…

CVE-2023-28284
MEDIUM 4.3 Network 1 apps

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2023-20950
MEDIUM

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-22880
MEDIUM 6.8 Network 1 apps

Zoom for Windows clients before version 5.13.3, Zoom Rooms for Windows clients before version 5.13.5 and Zoom VDI for Windows clients before 5.13.1 contain an …

CVE-2023-24923
MEDIUM 5.5 Local 1 apps

Microsoft OneDrive for Android Information Disclosure Vulnerability

CVE-2023-24890
MEDIUM 6.5 Network 1 apps

Microsoft OneDrive for iOS Security Feature Bypass Vulnerability

CVE-2023-24880
MEDIUM 4.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2021-29647
MEDIUM 5.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2021-33655
MEDIUM 6.7

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2023-21721
MEDIUM 6.5 Network 1 apps

Microsoft OneNote Elevation of Privilege Vulnerability

CVE-2022-39842
MEDIUM 6.1

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2022-36928
MEDIUM 6.1 Local 1 apps

Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit this vulnerability to read and write to …

CVE-2022-42721
MEDIUM 5.5

Indexed via Android Security Bulletin; full NVD metadata pending.

CVE-2018-16135
MEDIUM 6.5 Network 1 apps

The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.

CVE-2022-46880
MEDIUM 6.5 Network 1 apps

A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13t…

CVE-2022-46875
MEDIUM 6.5 Network 1 apps

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue onl…

CVE-2022-45420
MEDIUM 6.5 Network 1 apps

Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user …

CVE-2022-45418
MEDIUM 6.1 Network 1 apps

If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user con…

CVE-2022-45416
MEDIUM 6.5 Network 1 apps

Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have…