Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

845 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2025-55226
CRITICAL 6.7

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-55224
CRITICAL 7.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-54918
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-53800
CRITICAL 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-9187
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-9179
CRITICAL 9.8 Réseau 1 apps

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents sl…

CVE-2025-53766
CRITICAL 9.8 Réseau 1 apps

Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

CVE-2025-53778
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-50177
CRITICAL 8.1

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

CVE-2025-50176
CRITICAL 7.8

DirectX Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-50165
CRITICAL 9.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-48807
CRITICAL 6.7

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-8044
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-8043
CRITICAL 9.8 Réseau 1 apps

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Firefox 141.

CVE-2025-8038
CRITICAL 9.8 Réseau 1 apps

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox 141, Firefox ESR 140.1, Thunderbird 141…

CVE-2025-8037
CRITICAL 9.1 Réseau 1 apps

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie includ…

CVE-2025-8031
CRITICAL 9.8 Réseau 1 apps

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability …

CVE-2025-8028
CRITICAL 9.8 Réseau 1 apps

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect compu…

CVE-2025-49735
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-48822
CRITICAL 8.6

Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability

CVE-2025-47981
CRITICAL 9.8

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

CVE-2025-47980
CRITICAL 6.2

Windows Imaging Component Information Disclosure Vulnerability

CVE-2024-36357
CRITICAL 5.6

AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue

CVE-2024-36350
CRITICAL 5.6

AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue

CVE-2025-33071
CRITICAL 8.1

Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability

CVE-2025-33070
CRITICAL 8.1

Windows Netlogon Elevation of Privilege Vulnerability

CVE-2025-32710
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-29828
CRITICAL 8.1

Windows Schannel Remote Code Execution Vulnerability

CVE-2025-4918
CRITICAL 9.8 Réseau 1 apps

An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 1…

CVE-2025-29967
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29966
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-29833
CRITICAL 7.7

Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability

CVE-2025-4083
CRITICAL 9.1 Réseau 1 apps

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level docu…

CVE-2025-27491
CRITICAL 7.1

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-27482
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-27480
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-26686
CRITICAL 7.5

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2025-26670
CRITICAL 8.1

Lightweight Directory Access Protocol (LDAP) Client Remote Code Execution Vulnerability

CVE-2025-26663
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2025-26645
CRITICAL 8.8

Remote Desktop Client Remote Code Execution Vulnerability

CVE-2025-24084
CRITICAL 8.4

Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability

CVE-2025-24064
CRITICAL 8.1

Windows Domain Name Service Remote Code Execution Vulnerability

CVE-2025-24045
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-24035
CRITICAL 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

CVE-2025-1942
CRITICAL 9.8 Réseau 1 apps

When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability …

CVE-2025-21379
CRITICAL 7.1

DHCP Client Service Remote Code Execution Vulnerability

CVE-2025-21376
CRITICAL 8.1

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

CVE-2025-1020
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-1017
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1016
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bug…