Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2022-24480
MEDIUM 6.3 Physique 1 apps

Outlook for Android Elevation of Privilege Vulnerability

CVE-2022-44698
MEDIUM 5.4 KEV

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2022-43363
MEDIUM 6.1 Réseau 2 apps

Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati…

CVE-2022-20468
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20466
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-41099
MEDIUM 4.6 Physique

BitLocker Security Feature Bypass Vulnerability

CVE-2022-41098
MEDIUM 5.5 Local

Windows GDI+ Information Disclosure Vulnerability

CVE-2022-41097
MEDIUM 6.5 Réseau

Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability

CVE-2022-41091
MEDIUM 5.4 KEV Réseau

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-41090
MEDIUM 5.9 Réseau

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

CVE-2022-41086
MEDIUM 6.4 Local

Windows Group Policy Elevation of Privilege Vulnerability

CVE-2022-41055
MEDIUM 5.5 Local

Windows Human Interface Device Information Disclosure Vulnerability

CVE-2022-41049
MEDIUM 5.4 KEV Réseau

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2022-38015
MEDIUM 6.5 Local

Windows Hyper-V Denial of Service Vulnerability

CVE-2022-20454
MEDIUM 6.7

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20415
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20412
MEDIUM 6.7

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20409
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-39758
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-20197
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-4189
MEDIUM 5.3 Réseau 1 apps

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the …

CVE-2017-20052
MEDIUM 5.0 Réseau 1 apps

A vulnerability classified as problematic was found in Python 2.7.13. This vulnerability affects unknown code of the component pgAdmin4. The manipulation leads…

CVE-2022-32550
MEDIUM 4.8 Réseau 4 apps

An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password servic…

CVE-2022-25375
MEDIUM 5.5

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-25258
MEDIUM 4.6

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-29868
MEDIUM 5.5 Local 1 apps

1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate…

CVE-2021-39700
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-26558
MEDIUM 4.2

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2020-20096
MEDIUM 6.5 Réseau 2 apps

Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofin…

CVE-2021-3733
MEDIUM 6.5 Réseau 1 apps

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects …

CVE-2021-39689
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2022-23255
MEDIUM 5.9 Physique 1 apps

Microsoft OneDrive for Android Security Feature Bypass Vulnerability

CVE-2013-3900
MEDIUM 5.5 KEV

WinVerifyTrust Signature Validation Vulnerability

CVE-2021-43546
MEDIUM 4.3 Réseau 1 apps

It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefo…

CVE-2021-43545
MEDIUM 6.5 Réseau 1 apps

Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0,…

CVE-2021-43543
MEDIUM 6.1 Réseau 1 apps

Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects…

CVE-2021-43542
MEDIUM 6.5 Réseau 1 apps

Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff…

CVE-2021-43541
MEDIUM 6.5 Réseau 1 apps

When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder…

CVE-2021-43538
MEDIUM 4.3 Réseau 1 apps

By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock…

CVE-2021-43536
MEDIUM 6.5 Réseau 1 apps

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < …

CVE-2021-43528
MEDIUM 6.5 Réseau 1 apps

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level…

CVE-2021-38509
MEDIUM 4.3 Réseau 1 apps

Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a…

CVE-2021-38508
MEDIUM 4.3 Réseau 1 apps

By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav…

CVE-2021-38507
MEDIUM 6.5 Réseau 1 apps

The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT…

CVE-2021-38506
MEDIUM 4.3 Réseau 1 apps

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on…

CVE-2021-38505
MEDIUM 6.5 Réseau 1 apps

Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it…

CVE-2021-0969
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0961
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0958
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-38502
MEDIUM 5.9 Réseau 1 apps

Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted mes…