Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2019-9936
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-6812
MEDIUM 5.3 Réseau 1 apps

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microp…

CVE-2020-10570
MEDIUM 6.1 Physique 1 apps

The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on me…

CVE-2019-12278
MEDIUM 4.3 Réseau 1 apps

Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several …

CVE-2020-6798
MEDIUM 6.1 Réseau 1 apps

If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that …

CVE-2020-6797
MEDIUM 4.3 Réseau 1 apps

By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is re…

CVE-2020-6795
MEDIUM 6.5 Réseau 1 apps

When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploi…

CVE-2020-6794
MEDIUM 6.5 Réseau 1 apps

If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is becau…

CVE-2020-6793
MEDIUM 6.5 Réseau 1 apps

When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird…

CVE-2020-6792
MEDIUM 4.3 Réseau 1 apps

When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 6…

CVE-2020-0044
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0043
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0042
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0022
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2013-5112
MEDIUM 4.6 Physique 1 apps

Evernote before 5.5.1 has insecure PIN storage

CVE-2020-8492
MEDIUM 6.5 Réseau 1 apps

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression …

CVE-2020-8315
MEDIUM 5.5 Local 1 apps

In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacke…

CVE-2019-1460
MEDIUM 4.6 Réseau 1 apps

A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing…

CVE-2019-20372
MEDIUM 5.3 Réseau 1 apps

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized …

CVE-2014-3753
MEDIUM 5.5 Local 1 apps

AgileBits 1Password through 1.0.9.340 allows security feature bypass

CVE-2019-11763
MEDIUM 6.1 Réseau 1 apps

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML commen…

CVE-2019-11762
MEDIUM 6.1 Réseau 1 apps

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on …

CVE-2019-11761
MEDIUM 5.4 Réseau 1 apps

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this o…

CVE-2020-0002
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0001
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-19788
MEDIUM 5.5 Local 1 apps

Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe i…

CVE-2019-8719
MEDIUM 6.1 Réseau 1 apps

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win…

CVE-2019-8625
MEDIUM 6.1 Réseau 1 apps

A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win…

CVE-2019-2223
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-2222
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-2221
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2016-1000110
MEDIUM 6.1 Réseau 1 apps

The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker t…

CVE-2019-11135
MEDIUM 6.5 Local

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via …

CVE-2019-11833
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-18348
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a u…

CVE-2019-2186
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-2185
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-16935
MEDIUM 6.1 Réseau 1 apps

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/Do…

CVE-2019-11744
MEDIUM 6.1 Réseau 1 apps

Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is possible to pass a li…

CVE-2019-11742
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a &lt;canvas&gt; element due to an err…

CVE-2019-11739
MEDIUM 6.5 Réseau 1 apps

Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunde…

CVE-2019-16248
MEDIUM 5.5 Local 1 apps

The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a p…

CVE-2019-14319
MEDIUM 6.5 Réseau adjacent 2 apps

The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker…

CVE-2019-15514
MEDIUM 5.3 Réseau 2 apps

The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attac…

CVE-2019-1948
MEDIUM 5.9 Réseau 1 apps

A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by usin…

CVE-2019-1218
MEDIUM 5.4 Réseau 1 apps

A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit t…

CVE-2019-2125
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-1105
MEDIUM 5.4 Réseau 1 apps

A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could e…

CVE-2019-9817
MEDIUM 5.3 Réseau 1 apps

Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violati…

CVE-2019-9816
MEDIUM 5.9 Réseau 1 apps

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch…