Vulnérabilités
Vulnérabilités des apps suivies
2 321 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2019-11730
MEDIUM 6.5
Réseau 1 apps
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo… |
|
CVE-2019-11717
MEDIUM 5.3
Réseau 1 apps
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible … |
|
CVE-2019-11715
MEDIUM 6.1
Réseau 1 apps
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa… |
|
CVE-2019-11698
MEDIUM 5.3
Réseau 1 apps
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten… |
|
CVE-2019-1084
MEDIUM 6.5
Réseau 2 apps
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated a… |
|
CVE-2018-20852
MEDIUM 5.3
Réseau 1 apps
http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se… |
|
CVE-2019-13450
MEDIUM 6.5
Réseau 1 apps
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.… |
|
CVE-2019-13449
MEDIUM 6.5
Réseau 1 apps
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&c… |
|
CVE-2019-13118
MEDIUM 5.3
Réseau 1 apps
In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination coul… |
|
CVE-2019-0948
MEDIUM 4.7
Windows Event Viewer Information Disclosure Vulnerability |
|
CVE-2018-18524
MEDIUM 6.1
Réseau 1 apps
Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. Af… |
|
CVE-2019-3566
MEDIUM 5.9
Réseau 1 apps
A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover pre… |
|
CVE-2019-2054
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-2043
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-11819
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-9801
MEDIUM 5.3
Réseau 1 apps
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows o… |
|
CVE-2019-9793
MEDIUM 5.9
Réseau 1 apps
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnera… |
|
CVE-2018-18509
MEDIUM 5.3
Réseau 1 apps
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message… |
|
CVE-2019-9970
MEDIUM 6.5
Réseau 1 apps
Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homogr… |
|
CVE-2019-9947
MEDIUM 6.1
Réseau 1 apps
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u… |
|
CVE-2019-9740
MEDIUM 6.1
Réseau 1 apps
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u… |
|
CVE-2019-2005
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-18499
MEDIUM 6.5
Réseau 1 apps
A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to anothe… |
|
CVE-2018-18494
MEDIUM 6.5
Réseau 1 apps
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another sit… |
|
CVE-2019-1677
MEDIUM 4.6
Local 1 apps
A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-site scripting attack against the applica… |
|
CVE-2018-20251
MEDIUM 5.5
Local 1 apps
In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNA… |
|
CVE-2019-7317
MEDIUM 5.3
Réseau 1 apps
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. |
|
CVE-2017-18009
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2016-6684
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2019-0622
MEDIUM 4.6
Physique 1 apps
An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevati… |
|
CVE-2018-3986
MEDIUM 5.5
Local 1 apps
An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android messaging application version 4.9.0. The… |
|
CVE-2018-20351
MEDIUM 6.1
Réseau 1 apps
The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832. |
|
CVE-2018-3988
MEDIUM 4.7
Local 1 apps
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attac… |
|
CVE-2018-16845
MEDIUM 6.1
Local 1 apps
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, … |
|
CVE-2018-9541
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-12383
MEDIUM 5.5
Local 1 apps
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because t… |
|
CVE-2018-12374
MEDIUM 4.3
Réseau 1 apps
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects … |
|
CVE-2018-12373
MEDIUM 6.5
Réseau 1 apps
dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderb… |
|
CVE-2018-12372
MEDIUM 6.5
Réseau 1 apps
Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thu… |
|
CVE-2018-12367
MEDIUM 4.3
Réseau 1 apps
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals… |
|
CVE-2018-12366
MEDIUM 6.5
Réseau 1 apps
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private dat… |
|
CVE-2018-12365
MEDIUM 6.5
Réseau 1 apps
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. Th… |
|
CVE-2018-15543
MEDIUM 6.8
Physique 1 apps
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authenticati… |
|
CVE-2018-15542
MEDIUM 6.4
Physique 1 apps
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulatio… |
|
CVE-2018-13042
MEDIUM 5.9
Réseau 1 apps
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo… |
|
CVE-2018-9452
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-6976
MEDIUM 5.3
Réseau 1 apps
The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted file… |
|
CVE-2018-9488
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-9440
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2018-11270
MEDIUM
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |