Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

2 321 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2019-11730
MEDIUM 6.5 Réseau 1 apps

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo…

CVE-2019-11717
MEDIUM 5.3 Réseau 1 apps

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible …

CVE-2019-11715
MEDIUM 6.1 Réseau 1 apps

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa…

CVE-2019-11698
MEDIUM 5.3 Réseau 1 apps

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten…

CVE-2019-1084
MEDIUM 6.5 Réseau 2 apps

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated a…

CVE-2018-20852
MEDIUM 5.3 Réseau 1 apps

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se…

CVE-2019-13450
MEDIUM 6.5 Réseau 1 apps

In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active.…

CVE-2019-13449
MEDIUM 6.5 Réseau 1 apps

In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&c…

CVE-2019-13118
MEDIUM 5.3 Réseau 1 apps

In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination coul…

CVE-2019-0948
MEDIUM 4.7

Windows Event Viewer Information Disclosure Vulnerability

CVE-2018-18524
MEDIUM 6.1 Réseau 1 apps

Evernote 6.15 on Windows has an incorrectly repaired stored XSS vulnerability. An attacker can use this XSS issue to inject Node.js code under Present mode. Af…

CVE-2019-3566
MEDIUM 5.9 Réseau 1 apps

A bug in WhatsApp for Android's messaging logic would potentially allow a malicious individual who has taken over over a WhatsApp user's account to recover pre…

CVE-2019-2054
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-2043
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-11819
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-9801
MEDIUM 5.3 Réseau 1 apps

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows o…

CVE-2019-9793
MEDIUM 5.9 Réseau 1 apps

A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnera…

CVE-2018-18509
MEDIUM 5.3 Réseau 1 apps

A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message…

CVE-2019-9970
MEDIUM 6.5 Réseau 1 apps

Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homogr…

CVE-2019-9947
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u…

CVE-2019-9740
MEDIUM 6.1 Réseau 1 apps

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a u…

CVE-2019-2005
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-18499
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to anothe…

CVE-2018-18494
MEDIUM 6.5 Réseau 1 apps

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another sit…

CVE-2019-1677
MEDIUM 4.6 Local 1 apps

A vulnerability in Cisco Webex Meetings for Android could allow an unauthenticated, local attacker to perform a cross-site scripting attack against the applica…

CVE-2018-20251
MEDIUM 5.5 Local 1 apps

In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. The UNACE module (UNA…

CVE-2019-7317
MEDIUM 5.3 Réseau 1 apps

png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.

CVE-2017-18009
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2016-6684
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2019-0622
MEDIUM 4.6 Physique 1 apps

An elevation of privilege vulnerability exists when Skype for Andriod fails to properly handle specific authentication requests, aka "Skype for Android Elevati…

CVE-2018-3986
MEDIUM 5.5 Local 1 apps

An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android messaging application version 4.9.0. The…

CVE-2018-20351
MEDIUM 6.1 Réseau 1 apps

The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.

CVE-2018-3988
MEDIUM 4.7 Local 1 apps

Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attac…

CVE-2018-16845
MEDIUM 6.1 Local 1 apps

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, …

CVE-2018-9541
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-12383
MEDIUM 5.5 Local 1 apps

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because t…

CVE-2018-12374
MEDIUM 4.3 Réseau 1 apps

Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects …

CVE-2018-12373
MEDIUM 6.5 Réseau 1 apps

dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderb…

CVE-2018-12372
MEDIUM 6.5 Réseau 1 apps

Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thu…

CVE-2018-12367
MEDIUM 4.3 Réseau 1 apps

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals…

CVE-2018-12366
MEDIUM 6.5 Réseau 1 apps

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private dat…

CVE-2018-12365
MEDIUM 6.5 Réseau 1 apps

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. Th…

CVE-2018-15543
MEDIUM 6.8 Physique 1 apps

An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authenticati…

CVE-2018-15542
MEDIUM 6.4 Physique 1 apps

An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulatio…

CVE-2018-13042
MEDIUM 5.9 Réseau 1 apps

The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo…

CVE-2018-9452
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-6976
MEDIUM 5.3 Réseau 1 apps

The VMware Content Locker for iOS prior to 4.14 contains a data protection vulnerability in the SQLite database. This vulnerability relates to unencrypted file…

CVE-2018-9488
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-9440
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2018-11270
MEDIUM

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.