Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2020-26951
MEDIUM 6.1 Réseau 1 apps

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of expl…

CVE-2020-29660
MEDIUM 4.4

A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may al…

CVE-2020-24441
MEDIUM 5.5 Local 1 apps

Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in…

CVE-2020-15436
MEDIUM 6.7

Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging …

CVE-2020-1908
MEDIUM 4.6 Physique 1 apps

Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could have permitted use of Siri to interact wit…

CVE-2020-0415
MEDIUM 5.5 Local

In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of cont…

CVE-2020-15646
MEDIUM 5.9 Réseau 1 apps

If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attack…

CVE-2020-1904
MEDIUM 5.5 Local 1 apps

A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwr…

CVE-2020-1903
MEDIUM 5.5 Local 1 apps

An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulte…

CVE-2020-1901
MEDIUM 5.3 Réseau 1 apps

Receiving a large text message containing URLs in WhatsApp for iOS prior to v2.20.91.4 could have caused the application to freeze while processing the message.

CVE-2020-15677
MEDIUM 6.1 Réseau 1 apps

By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original s…

CVE-2020-15676
MEDIUM 6.1 Réseau 1 apps

Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attack…

CVE-2019-2194
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-12464
MEDIUM 6.7

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2020-10768
MEDIUM 5.5

A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function where it can be used to enable indirect branch speculation after it has been disabl…

CVE-2020-10767
MEDIUM 5.5

A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will b…

CVE-2020-10766
MEDIUM 5.5

A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to…

CVE-2017-8246
MEDIUM 7.8

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2020-1574
MEDIUM 5.5 Local

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory. An attacker who successfully exploited…

CVE-2020-8647
MEDIUM 6.1

Microsoft Security Update Guide entry — NVD enrichira.

CVE-2020-15658
MEDIUM 6.5 Réseau 1 apps

The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier p…

CVE-2020-15655
MEDIUM 6.5 Réseau 1 apps

A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-ori…

CVE-2020-15654
MEDIUM 6.5 Réseau 1 apps

When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are …

CVE-2020-15653
MEDIUM 6.5 Réseau 1 apps

An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying o…

CVE-2020-15652
MEDIUM 6.5 Réseau 1 apps

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content …

CVE-2020-15648
MEDIUM 6.5 Réseau 1 apps

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affec…

CVE-2020-12421
MEDIUM 6.5 Réseau 1 apps

When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) …

CVE-2020-12418
MEDIUM 6.5 Réseau 1 apps

Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affec…

CVE-2020-12405
MEDIUM 5.3 Réseau 1 apps

When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects…

CVE-2020-12399
MEDIUM 4.4 Local 1 apps

NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thund…

CVE-2020-14422
MEDIUM 5.9 Réseau 1 apps

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to…

CVE-2020-13631
MEDIUM 5.5 Local 1 apps

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

CVE-2020-12392
MEDIUM 5.5 Local 1 apps

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user …

CVE-2020-13434
MEDIUM 5.5 Local 1 apps

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

CVE-2020-12397
MEDIUM 4.3 Réseau 1 apps

By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerab…

CVE-2020-5753
MEDIUM 5.3 Réseau 1 apps

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used…

CVE-2020-12474
MEDIUM 6.5 Réseau 2 apps

Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public U…

CVE-2020-0104
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-11008
MEDIUM 4.0 Réseau 1 apps

Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is simi…

CVE-2020-0935
MEDIUM 5.5 Local 1 apps

An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows E…

CVE-2020-11765
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, le…

CVE-2020-11764
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

CVE-2020-11763
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

CVE-2020-11762
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling th…

CVE-2020-11761
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfF…

CVE-2020-11760
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

CVE-2020-11759
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineB…

CVE-2020-11758
MEDIUM 5.5 Local 1 apps

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

CVE-2020-0077
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0075
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.