Vulnérabilités
Vulnérabilités des apps suivies
1 706 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-38039
LOW
Hackerone: CVE-2023-38039 HTTP headers eat all memory |
|
CVE-2023-40435
MEDIUM 5.5
Local 1 apps
This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials. |
|
CVE-2023-39215
HIGH 7.1
Réseau 4 apps
Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2022-32920
MEDIUM 5.5
Local 1 apps
The issue was addressed with improved checks. This issue is fixed in Xcode 14.0. Parsing a file may lead to disclosure of user information. |
|
CVE-2023-39214
HIGH 7.6
Réseau 4 apps
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. |
|
CVE-2023-39218
MEDIUM 6.1
Réseau 4 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-36535
HIGH 7.1
Réseau 4 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network acc… |
|
CVE-2023-36532
MEDIUM 5.9
Réseau 4 apps
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
|
CVE-2023-31486
HIGH 8.1
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2023-36539
MEDIUM 5.3
Réseau 4 apps
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-32395
MEDIUM 5.5
Local
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS Ventura 13.4. An app may … |
|
CVE-2023-34114
HIGH 7.4
Réseau 2 apps
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor… |
|
CVE-2023-28600
MEDIUM 5.2
Local 1 apps
Zoom for MacOSclients prior to 5.14.0 contain an improper access control vulnerability. A malicious user may be able to delete/replace Zoom Client files poten… |
|
CVE-2023-28599
MEDIUM 4.3
Réseau 4 apps
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-27967
HIGH 8.6
Local 1 apps
The issue was addressed with improved memory handling. This issue is fixed in Xcode 14.3. An app may be able to execute arbitrary code out of its sandbox or wi… |
|
CVE-2023-27952
MEDIUM 4.7
Local
A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks. |
|
CVE-2023-27945
MEDIUM 6.3
Local 1 apps
This issue was addressed with improved entitlements. This issue is fixed in Xcode 14.3, macOS Big Sur 11.7.7, macOS Monterey 12.6.6. A sandboxed app may be abl… |
|
CVE-2023-27043
MEDIUM 5.3
Réseau 1 apps
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is ident… |
|
CVE-2023-31484
HIGH 8.1
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
|
CVE-2023-28597
HIGH 8.3
Réseau adjacent 4 apps
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later … |
|
CVE-2022-42797
HIGH 7.8
Local 1 apps
An injection issue was addressed with improved input validation. This issue is fixed in Xcode 14.1. An app may be able to gain root privileges. |
|
CVE-2022-39260
HIGH 8.5
Réseau 2 apps
Git is an open source, scalable, distributed revision control system. `git shell` is a restricted login shell that can be used to implement Git's push/pull fun… |
|
CVE-2022-39253
HIGH 5.5
Local 2 apps
Git is an open source, scalable, distributed revision control system. Versions prior to 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 are … |
|
CVE-2022-29187
HIGH 7.8
Local 2 apps
Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privil… |
|
CVE-2022-32550
MEDIUM 4.8
Réseau 4 apps
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic… |
|
CVE-2022-26747
HIGH 7.8
Local 1 apps
This issue was addressed with improved checks. This issue is fixed in Xcode 13.4. An app may be able to gain elevated privileges. |
|
CVE-2022-29868
MEDIUM 5.5
Local 1 apps
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate… |
|
CVE-2022-24765
HIGH 6.0
Local 2 apps
Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties … |
|
CVE-2022-22608
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22607
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22606
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22605
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22604
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22603
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22602
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2022-22601
HIGH 7.8
Local 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 13.3. Opening a maliciously crafted file may lead to unexpected… |
|
CVE-2021-44228
CRITICAL 10.0
KEV
Réseau 1 apps
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameter… |
|
CVE-2021-41795
MEDIUM 6.5
Réseau 1 apps
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable compo… |
|
CVE-2021-1800
MEDIUM 5.5
Local 1 apps
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files … |
|
CVE-2021-21300
CRITICAL 8.8
Réseau 2 apps
Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as f… |
|
CVE-2019-8840
HIGH 8.8
Réseau 1 apps
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in Xcode 11.3. Compiling with untrusted sources may lead to arbitrary co… |
|
CVE-2020-13428
HIGH 7.8
Local 1 apps
A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allow… |
|
CVE-2014-9390
CRITICAL 9.8
Réseau 2 apps
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows a… |
|
CVE-2019-20372
MEDIUM 5.3
Réseau 1 apps
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized … |
|
CVE-2019-8806
HIGH 7.8
Local 1 apps
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrar… |
|
CVE-2019-8800
HIGH 7.8
Local 1 apps
A memory corruption issue was addressed with improved validation. This issue is fixed in Xcode 11.2. Processing a maliciously crafted file may lead to arbitrar… |
|
CVE-2019-8739
HIGH 7.8
Local 1 apps
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to ar… |
|
CVE-2019-8738
HIGH 7.8
Local 1 apps
A memory corruption issue was addressed with improved state management. This issue is fixed in Xcode 11.0. Processing a maliciously crafted file may lead to ar… |
|
CVE-2019-8724
HIGH 8.8
Réseau 1 apps
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro… |
|
CVE-2019-8723
HIGH 8.8
Réseau 1 apps
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro… |