Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-29963
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29962
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29961
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29960
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29959
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29958
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29957
HIGH 6.2
Windows Deployment Services Denial of Service Vulnerability |
|
CVE-2025-29956
HIGH 5.4
Windows SMB Information Disclosure Vulnerability |
|
CVE-2025-29955
HIGH 6.2
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2025-29954
HIGH 5.9
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2025-29842
HIGH 7.5
UrlMon Security Feature Bypass Vulnerability |
|
CVE-2025-29841
HIGH 7.0
Universal Print Management Service Elevation of Privilege Vulnerability |
|
CVE-2025-29840
HIGH 8.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29839
HIGH 4.0
Windows Multiple UNC Provider Driver Information Disclosure Vulnerability |
|
CVE-2025-29838
HIGH 7.4
Windows ExecutionContext Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29837
HIGH 5.5
Windows Installer Information Disclosure Vulnerability |
|
CVE-2025-29836
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29835
HIGH 6.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2025-29833
CRITICAL 7.7
Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability |
|
CVE-2025-29832
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29831
HIGH 7.5
Windows Remote Desktop Services Remote Code Execution Vulnerability |
|
CVE-2025-29830
HIGH 6.5
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
|
CVE-2025-29829
HIGH 5.5
Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability |
|
CVE-2025-27468
HIGH 7.0
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2025-26677
HIGH 7.5
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
|
CVE-2025-24063
HIGH 7.8
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2025-4093
HIGH 8.1
Réseau 1 apps
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort thi… |
|
CVE-2025-4092
MEDIUM 6.5
Réseau 1 apps
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-4091
HIGH 8.1
Réseau 1 apps
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2025-4089
MEDIUM 5.1
Local 1 apps
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t… |
|
CVE-2025-4088
MEDIUM 6.5
Réseau 1 apps
A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo… |
|
CVE-2025-4087
MEDIUM 4.8
Réseau 1 apps
A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou… |
|
CVE-2025-4085
HIGH 7.1
Réseau 1 apps
An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive information or escalate privileges. Th… |
|
CVE-2025-4084
MEDIUM 5.7
Réseau 1 apps
Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi… |
|
CVE-2025-4083
CRITICAL 9.1
Réseau 1 apps
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level docu… |
|
CVE-2025-4082
MEDIUM 5.9
Réseau 1 apps
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate… |
|
CVE-2025-2817
HIGH 8.8
Réseau 1 apps
Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By… |
|
CVE-2022-47112
LOW 2.5
Local 1 apps
7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected. |
|
CVE-2022-47111
LOW 2.5
Local 1 apps
7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected. |
|
CVE-2025-3523
MEDIUM 6.4
Réseau 1 apps
When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove… |
|
CVE-2025-3522
MEDIUM 6.3
Réseau 1 apps
Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a… |
|
CVE-2025-2830
MEDIUM 6.3
Réseau 1 apps
By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t… |
|
CVE-2025-26687
HIGH 7.5
Réseau 1 apps
Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. |
|
CVE-2025-29824
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29812
HIGH 7.8
DirectX Graphics Kernel Elevation of Privilege Vulnerability |
|
CVE-2025-29811
HIGH 7.8
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29810
HIGH 7.5
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2025-29809
HIGH 7.1
Windows Kerberos Security Feature Bypass Vulnerability |
|
CVE-2025-29808
HIGH 5.5
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2025-27742
HIGH 5.5
NTFS Information Disclosure Vulnerability |