Vulnérabilités
Vulnérabilités des apps suivies
2 321 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-33744
MEDIUM 5.3
Local
Windows Secure Kernel Mode Security Feature Bypass Vulnerability |
|
CVE-2021-31961
MEDIUM 6.1
Local
Windows InstallService Elevation of Privilege Vulnerability |
|
CVE-2021-29957
MEDIUM 4.3
Réseau 1 apps
If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi… |
|
CVE-2021-29956
MEDIUM 4.3
Réseau 1 apps
OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass… |
|
CVE-2021-29951
MEDIUM 6.5
Réseau 1 apps
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th… |
|
CVE-2021-29945
MEDIUM 6.5
Réseau 1 apps
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32… |
|
CVE-2021-23998
MEDIUM 6.5
Réseau 1 apps
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E… |
|
CVE-2021-23993
MEDIUM 6.5
Réseau 1 apps
An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub… |
|
CVE-2021-23992
MEDIUM 4.3
Réseau 1 apps
Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,… |
|
CVE-2021-23991
MEDIUM 6.8
Réseau 1 apps
If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b… |
|
CVE-2021-3426
MEDIUM 5.7
Réseau adjacent 1 apps
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server co… |
|
CVE-2021-31323
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty fu… |
|
CVE-2021-31322
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of thei… |
|
CVE-2021-31319
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their c… |
|
CVE-2021-31318
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function … |
|
CVE-2021-31317
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of … |
|
CVE-2021-31315
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of … |
|
CVE-2020-26146
MEDIUM 5.3
Réseau adjacent
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numb… |
|
CVE-2021-1906
MEDIUM
KEV
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2021-21211
MEDIUM 6.5
Réseau 1 apps
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML… |
|
CVE-2021-30496
MEDIUM 5.7
Réseau 1 apps
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied mes… |
|
CVE-2021-28312
MEDIUM 3.3
Windows NTFS Denial of Service Vulnerability |
|
CVE-2021-1467
MEDIUM 4.3
Réseau 1 apps
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is d… |
|
CVE-2021-1800
MEDIUM 5.5
Local 1 apps
A path handling issue was addressed with improved validation. This issue is fixed in Xcode 12.4. A malicious application may be able to access arbitrary files … |
|
CVE-2021-23984
MEDIUM 6.5
Réseau 1 apps
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, … |
|
CVE-2021-23982
MEDIUM 6.5
Réseau 1 apps
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on … |
|
CVE-2020-7463
MEDIUM 5.5
Local 1 apps
In FreeBSD 12.1-STABLE before r364644, 11.4-STABLE before r364651, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, improper handli… |
|
CVE-2021-23953
MEDIUM 4.3
Réseau 1 apps
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as c… |
|
CVE-2021-23973
MEDIUM 6.5
Réseau 1 apps
When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed infor… |
|
CVE-2021-23969
MEDIUM 4.3
Réseau 1 apps
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested … |
|
CVE-2021-23968
MEDIUM 4.3
Réseau 1 apps
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to… |
|
CVE-2021-24114
MEDIUM 5.7
Réseau 1 apps
Microsoft Teams iOS Information Disclosure Vulnerability |
|
CVE-2021-24100
MEDIUM 5.0
Local 1 apps
Microsoft Edge for Android Information Disclosure Vulnerability |
|
CVE-2021-23336
MEDIUM 5.9
Réseau 1 apps
The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to W… |
|
CVE-2021-27205
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure. |
|
CVE-2021-27204
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. |
|
CVE-2021-24080
MEDIUM 6.5
Windows Trust Verification API Denial of Service Vulnerability |
|
CVE-2020-15358
MEDIUM 5.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2021-23253
MEDIUM 5.3
Réseau 1 apps
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g.… |
|
CVE-2020-35111
MEDIUM 4.3
Réseau 1 apps
When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web co… |
|
CVE-2020-26978
MEDIUM 6.1
Réseau 1 apps
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on … |
|
CVE-2020-6159
MEDIUM 6.1
Réseau 1 apps
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain ci… |
|
CVE-2020-0500
MEDIUM 5.5
Local
In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa… |
|
CVE-2020-17153
MEDIUM 4.3
Réseau 1 apps
Microsoft Edge for Android Spoofing Vulnerability |
|
CVE-2020-26966
MEDIUM 6.5
Réseau 1 apps
Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; res… |
|
CVE-2020-26965
MEDIUM 6.5
Réseau 1 apps
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when… |
|
CVE-2020-26961
MEDIUM 6.5
Réseau 1 apps
When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver.… |
|
CVE-2020-26958
MEDIUM 6.1
Réseau 1 apps
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a… |
|
CVE-2020-26956
MEDIUM 6.1
Réseau 1 apps
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox … |
|
CVE-2020-26953
MEDIUM 4.3
Réseau 1 apps
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or other… |