Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

749 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-20876
MEDIUM 6.7 Local

Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVE-2026-20872
MEDIUM 6.5 Réseau

External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.

CVE-2026-20862
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally.

CVE-2026-20851
MEDIUM 6.2 Local

Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally.

CVE-2026-20847
MEDIUM 6.5 Réseau

Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network.

CVE-2026-20839
MEDIUM 5.5 Local

Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally.

CVE-2026-20838
MEDIUM 5.5 Local

Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-20835
MEDIUM 5.5 Local

Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally.

CVE-2026-20834
MEDIUM 4.6 Physique

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

CVE-2026-20829
MEDIUM 5.5 Local

Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally.

CVE-2026-20828
MEDIUM 4.6 Physique

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack.

CVE-2026-20827
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform…

CVE-2026-20825
MEDIUM 4.4 Local

Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally.

CVE-2026-20824
MEDIUM 5.5 Local

Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.

CVE-2026-20823
MEDIUM 5.5 Local

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

CVE-2026-20821
MEDIUM 6.2 Local

Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally.

CVE-2026-20819
MEDIUM 5.5 Local

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally.

CVE-2026-20812
MEDIUM 6.5 Réseau

Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network.

CVE-2026-20805
MEDIUM 5.5 KEV Local

Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

CVE-2026-0890
MEDIUM 5.4 Réseau 1 apps

Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunder…

CVE-2026-0888
MEDIUM 5.3 Réseau 1 apps

Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVE-2026-0887
MEDIUM 4.3 Réseau 1 apps

Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th…

CVE-2026-0886
MEDIUM 5.3 Réseau 1 apps

Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a…

CVE-2026-0885
MEDIUM 6.5 Réseau 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2026-0883
MEDIUM 5.3 Réseau 1 apps

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2025-14331
MEDIUM 6.5 Réseau 1 apps

Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 14…

CVE-2025-12084
MEDIUM 5.3 Réseau 1 apps

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail…

CVE-2025-13836
MEDIUM 7.5 Réseau 1 apps

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server…

CVE-2025-52331
MEDIUM 6.1 Réseau 1 apps

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the …

CVE-2025-6075
MEDIUM 5.5 Local 1 apps

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-11716
MEDIUM 6.5 Réseau 1 apps

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11712
MEDIUM 6.1 Réseau 1 apps

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5 Réseau 1 apps

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-59502
MEDIUM 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-10536
MEDIUM 6.2 Local 1 apps

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140…

CVE-2025-10532
MEDIUM 6.5 Réseau 1 apps

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird…

CVE-2025-10531
MEDIUM 5.4 Réseau 1 apps

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVE-2025-10529
MEDIUM 6.5 Réseau 1 apps

Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVE-2025-9181
MEDIUM 6.5 Réseau 1 apps

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T…

CVE-2025-53779
MEDIUM 7.2

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-8033
MEDIUM 6.5 Réseau 1 apps

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in…

CVE-2025-8027
MEDIUM 6.5 Réseau 1 apps

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner…

CVE-2025-49464
MEDIUM 6.5 Réseau 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

CVE-2025-46789
MEDIUM 6.5 Réseau 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVE-2025-49760
MEDIUM 3.5

Windows Storage Spoofing Vulnerability

CVE-2025-5986
MEDIUM 6.5 Réseau 1 apps

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-2884
MEDIUM 6.6 Local

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-3932
MEDIUM 6.5 Réseau 1 apps

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-4092
MEDIUM 6.5 Réseau 1 apps

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-4089
MEDIUM 5.1 Local 1 apps

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t…