Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

181 CVEs affect a tracked app or OS (Low, Windows). 0 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
181
Actively exploited
0
Publication window
2015-05-21 → 2026-09-17

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

181 entries Low Windows Clear all
CVE
CVE-2021-37964
LOW 3.3

Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point t…

CVE-2021-29948
LOW 2.5

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac…

CVE-2020-27895
LOW 3.3

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTune…

CVE-2020-17020
LOW 3.3

Microsoft Word Security Feature Bypass Vulnerability

CVE-2020-17046
LOW · vendor

Windows Error Reporting Denial of Service Vulnerability

CVE-2020-1195
LOW 3.1

An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who succe…

CVE-2019-13762
LOW 3.3

Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local cod…

CVE-2019-13679
LOW 3.3

Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.

CVE-2019-11743
LOW 3.7

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts …

CVE-2018-6053
LOW 3.3

Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing b…

CVE-2018-8366
LOW 3.1

An information disclosure vulnerability exists when the Microsoft Edge Fetch API incorrectly handles a filtered response type, aka "Microsoft Edge Information …

CVE-2018-8370
LOW 3.1

A information disclosure vulnerability exists when WebAudio Library improperly handles audio requests, aka "Microsoft Edge Information Disclosure Vulnerability…

CVE-2018-8136
LOW · vendor

Windows Remote Code Execution Vulnerability

CVE-2018-0919
LOW 3.3

Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft …

CVE-2018-0763
LOW 3.1

Microsoft Edge in Microsoft Windows 10 1703 and 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information …

CVE-2018-1000030
LOW 3.6

Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears t…

CVE-2017-11874
LOW 3.1

Microsoft Edge in Microsoft Windows 10 1703, 1709, Windows Server, version 1709, and ChakraCore allows an attacker to bypass Control Flow Guard (CFG) to run ar…

CVE-2017-11833
LOW 3.1

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to determine the o…

CVE-2017-11791
LOW 3.1

ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, an…

CVE-2016-7239
LOW 3.1

The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) …

CVE-2016-7227
LOW 3.1

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspe…

CVE-2016-7204
LOW 3.1

Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerabilit…

CVE-2016-7199
LOW 3.1

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state informati…

CVE-2016-3325
LOW 3.1

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Informa…

CVE-2016-3291
LOW 2.4

Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted …

CVE-2016-5166
LOW 3.1

The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:…

CVE-2016-3274
LOW 3.1

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browse…

CVE-2016-0175
LOW 3.3

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

CVE-2016-0125
LOW 3.1

Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web…

CVE-2015-1283
LOW · vendor

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote …

CVE-2015-4000
LOW 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which…

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM