Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2021-33744
MEDIUM 5.3 Local

Windows Secure Kernel Mode Security Feature Bypass Vulnerability

CVE-2021-31961
MEDIUM 6.1 Local

Windows InstallService Elevation of Privilege Vulnerability

CVE-2021-29957
MEDIUM 4.3 Réseau 1 apps

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi…

CVE-2021-29956
MEDIUM 4.3 Réseau 1 apps

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass…

CVE-2021-29951
MEDIUM 6.5 Réseau 1 apps

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th…

CVE-2021-29945
MEDIUM 6.5 Réseau 1 apps

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32…

CVE-2021-23998
MEDIUM 6.5 Réseau 1 apps

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E…

CVE-2021-23993
MEDIUM 6.5 Réseau 1 apps

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub…

CVE-2021-23992
MEDIUM 4.3 Réseau 1 apps

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,…

CVE-2021-23991
MEDIUM 6.8 Réseau 1 apps

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b…

CVE-2021-3426
MEDIUM 5.7 Réseau adjacent 1 apps

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co…

CVE-2021-31323
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty fu…

CVE-2021-31322
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of thei…

CVE-2021-31319
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their c…

CVE-2021-31318
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function …

CVE-2021-31317
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of …

CVE-2021-31315
MEDIUM 5.5 Local 2 apps

Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of …

CVE-2020-26146
MEDIUM 5.3 Réseau adjacent

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numb…

CVE-2021-1906
MEDIUM KEV

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-21211
MEDIUM 6.5 Réseau 1 apps

Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML…

CVE-2021-30496
MEDIUM 5.7 Réseau 1 apps

The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied mes…

CVE-2021-28312
MEDIUM 3.3

Windows NTFS Denial of Service Vulnerability

CVE-2021-1467
MEDIUM 4.3 Réseau 1 apps

A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is d…

CVE-2021-1800
MEDIUM 5.5 Local 1 apps

A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files …

CVE-2021-23984
MEDIUM 6.5 Réseau 1 apps

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, …

CVE-2021-23982
MEDIUM 6.5 Réseau 1 apps

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on …

CVE-2020-7463
MEDIUM 5.5 Local 1 apps

In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handli…

CVE-2021-23953
MEDIUM 4.3 Réseau 1 apps

If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as c…

CVE-2021-23973
MEDIUM 6.5 Réseau 1 apps

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed infor…

CVE-2021-23969
MEDIUM 4.3 Réseau 1 apps

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested …

CVE-2021-23968
MEDIUM 4.3 Réseau 1 apps

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to…

CVE-2021-24114
MEDIUM 5.7 Réseau 1 apps

Microsoft Teams iOS Information Disclosure Vulnerability

CVE-2021-24100
MEDIUM 5.0 Local 1 apps

Microsoft Edge for Android Information Disclosure Vulnerability

CVE-2021-23336
MEDIUM 5.9 Réseau 1 apps

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to W…

CVE-2021-27205
MEDIUM 5.5 Local 2 apps

Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.

CVE-2021-27204
MEDIUM 5.5 Local 2 apps

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.

CVE-2021-24080
MEDIUM 6.5

Windows Trust Verification API Denial of Service Vulnerability

CVE-2020-15358
MEDIUM 5.5

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2021-23253
MEDIUM 5.3 Réseau 1 apps

Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g.…

CVE-2020-35111
MEDIUM 4.3 Réseau 1 apps

When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web co…

CVE-2020-26978
MEDIUM 6.1 Réseau 1 apps

Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on …

CVE-2020-6159
MEDIUM 6.1 Réseau 1 apps

URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain ci…

CVE-2020-0500
MEDIUM 5.5 Local

In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa…

CVE-2020-17153
MEDIUM 4.3 Réseau 1 apps

Microsoft Edge for Android Spoofing Vulnerability

CVE-2020-26966
MEDIUM 6.5 Réseau 1 apps

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res…

CVE-2020-26965
MEDIUM 6.5 Réseau 1 apps

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when…

CVE-2020-26961
MEDIUM 6.5 Réseau 1 apps

When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.…

CVE-2020-26958
MEDIUM 6.1 Réseau 1 apps

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a…

CVE-2020-26956
MEDIUM 6.1 Réseau 1 apps

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox …

CVE-2020-26953
MEDIUM 4.3 Réseau 1 apps

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other…