Vulnérabilités
Vulnérabilités des apps suivies
2 321 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2019-9936
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-6812
MEDIUM 5.3
Réseau 1 apps
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microp… |
|
CVE-2020-10570
MEDIUM 6.1
Physique 1 apps
The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on me… |
|
CVE-2019-12278
MEDIUM 4.3
Réseau 1 apps
Opera through 53 on Android allows Address Bar Spoofing. Characters from several languages are displayed in Right-to-Left order, due to mishandling of several … |
|
CVE-2020-6798
MEDIUM 6.1
Réseau 1 apps
If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that … |
|
CVE-2020-6797
MEDIUM 4.3
Réseau 1 apps
By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is re… |
|
CVE-2020-6795
MEDIUM 6.5
Réseau 1 apps
When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploi… |
|
CVE-2020-6794
MEDIUM 6.5
Réseau 1 apps
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is becau… |
|
CVE-2020-6793
MEDIUM 6.5
Réseau 1 apps
When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability affects Thunderbird… |
|
CVE-2020-6792
MEDIUM 4.3
Réseau 1 apps
When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 6… |
|
CVE-2020-0044
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0043
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0042
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0022
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2013-5112
MEDIUM 4.6
Physique 1 apps
Evernote before 5.5.1 has insecure PIN storage |
|
CVE-2020-8492
MEDIUM 6.5
Réseau 1 apps
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression … |
|
CVE-2020-8315
MEDIUM 5.5
Local 1 apps
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacke… |
|
CVE-2019-1460
MEDIUM 4.6
Réseau 1 apps
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages, aka 'Outlook for Android Spoofing… |
|
CVE-2019-20372
MEDIUM 5.3
Réseau 1 apps
NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized … |
|
CVE-2014-3753
MEDIUM 5.5
Local 1 apps
AgileBits 1Password through 1.0.9.340 allows security feature bypass |
|
CVE-2019-11763
MEDIUM 6.1
Réseau 1 apps
Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML commen… |
|
CVE-2019-11762
MEDIUM 6.1
Réseau 1 apps
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on … |
|
CVE-2019-11761
MEDIUM 5.4
Réseau 1 apps
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this o… |
|
CVE-2020-0002
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2020-0001
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-19788
MEDIUM 5.5
Local 1 apps
Opera for Android before 54.0.2669.49432 is vulnerable to a sandboxed cross-origin iframe bypass attack. By using a service working inside a sandboxed iframe i… |
|
CVE-2019-8719
MEDIUM 6.1
Réseau 1 apps
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2019-8625
MEDIUM 6.1
Réseau 1 apps
A logic issue was addressed with improved state management. This issue is fixed in tvOS 13, iTunes for Windows 12.10.1, iCloud for Windows 10.7, iCloud for Win… |
|
CVE-2019-2223
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-2222
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-2221
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2016-1000110
MEDIUM 6.1
Réseau 1 apps
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker t… |
|
CVE-2019-11135
MEDIUM 6.5
Local
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via … |
|
CVE-2019-11833
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-18348
MEDIUM 6.1
Réseau 1 apps
An issue was discovered in urllib2 in Python 2.x through 2.7.17 and urllib in Python 3.x through 3.8.0. CRLF injection is possible if the attacker controls a u… |
|
CVE-2019-2186
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-2185
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-16935
MEDIUM 6.1
Réseau 1 apps
The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/Do… |
|
CVE-2019-11744
MEDIUM 6.1
Réseau 1 apps
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a li… |
|
CVE-2019-11742
MEDIUM 6.5
Réseau 1 apps
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> element due to an err… |
|
CVE-2019-11739
MEDIUM 6.5
Réseau 1 apps
Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunde… |
|
CVE-2019-16248
MEDIUM 5.5
Local 1 apps
The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a p… |
|
CVE-2019-14319
MEDIUM 6.5
Réseau adjacent 2 apps
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker… |
|
CVE-2019-15514
MEDIUM 5.3
Réseau 2 apps
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attac… |
|
CVE-2019-1948
MEDIUM 5.9
Réseau 1 apps
A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by usin… |
|
CVE-2019-1218
MEDIUM 5.4
Réseau 1 apps
A spoofing vulnerability exists in the way Microsoft Outlook iOS software parses specifically crafted email messages. An authenticated attacker could exploit t… |
|
CVE-2019-2125
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-1105
MEDIUM 5.4
Réseau 1 apps
A spoofing vulnerability exists in the way Microsoft Outlook for Android software parses specifically crafted email messages. An authenticated attacker could e… |
|
CVE-2019-9817
MEDIUM 5.3
Réseau 1 apps
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violati… |
|
CVE-2019-9816
MEDIUM 5.9
Réseau 1 apps
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch… |