Vulnérabilités
Vulnérabilités des apps suivies
1 706 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2019-8722
HIGH 8.8
Réseau 1 apps
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro… |
|
CVE-2019-8721
HIGH 8.8
Réseau 1 apps
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without pro… |
|
CVE-2019-17051
HIGH 7.8
Local 1 apps
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-cl… |
|
CVE-2019-14379
CRITICAL 9.8
Réseau 1 apps
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manage… |
|
CVE-2019-13567
HIGH 8.8
Réseau 1 apps
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the h… |
|
CVE-2019-13450
MEDIUM 6.5
Réseau 1 apps
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.… |
|
CVE-2019-13449
MEDIUM 6.5
Réseau 1 apps
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&c… |
|
CVE-2019-10038
HIGH 7.8
Local 1 apps
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file such as the /Applications/Calculator.a… |
|
CVE-2018-4357
HIGH 7.8
Local 1 apps
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to Xcode 10. |
|
CVE-2019-3855
HIGH 8.8
Réseau 1 apps
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remot… |
|
CVE-2018-20351
MEDIUM 6.1
Réseau 1 apps
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. |
|
CVE-2018-20058
HIGH 7.5
Réseau 1 apps
In Evernote before 7.6 on macOS, there is a local file path traversal issue in attachment previewing, aka MACOSNOTE-28634. |
|
CVE-2018-15715
CRITICAL 9.8
Réseau 2 apps
Zoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are vulnerable to unauth… |
|
CVE-2018-16845
MEDIUM 6.1
Local 1 apps
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, … |
|
CVE-2018-16844
HIGH 7.5
Réseau 1 apps
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx co… |
|
CVE-2018-16843
HIGH 7.5
Réseau 1 apps
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects… |
|
CVE-2018-1167
HIGH 8.8
Réseau 3 apps
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is requir… |
|
CVE-2018-4164
CRITICAL 9.8
Réseau 1 apps
An issue was discovered in certain Apple products. Xcode before 9.3 is affected. The issue, which is unspecified, involves the "LLVM" component. |
|
CVE-2017-7167
HIGH 7.8
Local 1 apps
An issue was discovered in certain Apple products. Xcode before 9.2 is affected. The issue involves the "ld64" component. A buffer overflow allows remote attac… |
|
CVE-2017-7137
HIGH 7.8
Local 1 apps
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute a… |
|
CVE-2017-7136
HIGH 7.8
Local 1 apps
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute a… |
|
CVE-2017-7135
HIGH 7.8
Local 1 apps
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute a… |
|
CVE-2017-7134
HIGH 7.8
Local 1 apps
An issue was discovered in certain Apple products. Xcode before 9 is affected. The issue involves the "ld64" component. It allows remote attackers to execute a… |
|
CVE-2017-7529
HIGH 7.5
Réseau 1 apps
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of pote… |
|
CVE-2017-2391
MEDIUM 5.3
Réseau 9 apps
An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3… |
|
CVE-2016-1246
HIGH 7.5
Réseau
Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to a… |
|
CVE-2016-4705
HIGH 7.8
Local 1 apps
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vect… |
|
CVE-2016-4704
HIGH 7.8
Local 1 apps
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vect… |
|
CVE-2016-1765
HIGH 7.8
Local 1 apps
otool in Apple Xcode before 7.3 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified ve… |
|
CVE-2016-0747
MEDIUM 5.3
Réseau 1 apps
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service… |
|
CVE-2016-0746
CRITICAL 9.8
Réseau 1 apps
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker… |
|
CVE-2016-0742
HIGH 7.5
Réseau 1 apps
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process… |
|
CVE-2015-7057
N/A
1 apps
otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different … |
|
CVE-2015-7056
N/A
1 apps
IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic circumsta… |
|
CVE-2015-7049
N/A
1 apps
otools in Apple Xcode before 7.2 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted mach-o file, a different … |
|
CVE-2015-7030
N/A
1 apps
The Swift implementation in Apple Xcode before 7.1 mishandles type conversion, which has unspecified impact and attack vectors. |
|
CVE-2015-5910
N/A
1 apps
IDE Xcode Server in Apple Xcode before 7.0 does not ensure that server traffic is encrypted, which allows remote attackers to obtain sensitive information by s… |
|
CVE-2015-5909
N/A
1 apps
IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain potentially se… |
|
CVE-2015-3187
N/A
1 apps
The svn_repos_trace_node_locations function in Apache Subversion before 1.7.21 and 1.8.x before 1.8.14, when path-based authorization is used, allows remote au… |
|
CVE-2015-3184
N/A
1 apps
mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous access, whi… |
|
CVE-2015-3185
N/A
1 apps
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associat… |
|
CVE-2015-3027
N/A
1 apps
Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointers, which … |
|
CVE-2015-1149
N/A
1 apps
Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecifi… |
|
CVE-2015-0251
N/A
1 apps
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a cra… |
|
CVE-2015-0248
N/A
1 apps
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (a… |
|
CVE-2014-8108
N/A
1 apps
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.7.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of servic… |
|
CVE-2014-3580
N/A
1 apps
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service … |
|
CVE-2014-6394
N/A
1 apps
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attacker… |
|
CVE-2014-3528
N/A
1 apps
Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, w… |
|
CVE-2014-3522
N/A
1 apps
The Serf RA layer in Apache Subversion 1.4.0 through 1.7.x before 1.7.18 and 1.8.x before 1.8.10 does not properly handle wildcards in the Common Name (CN) or … |