Vulnérabilités
Vulnérabilités des apps suivies
749 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-20876
MEDIUM 6.7
Local
Heap-based buffer overflow in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. |
|
CVE-2026-20872
MEDIUM 6.5
Réseau
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-20862
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Management Services allows an authorized attacker to disclose information locally. |
|
CVE-2026-20851
MEDIUM 6.2
Local
Out-of-bounds read in Capability Access Management Service (camsvc) allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20847
MEDIUM 6.5
Réseau
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to perform spoofing over a network. |
|
CVE-2026-20839
MEDIUM 5.5
Local
Improper access control in Windows Client-Side Caching (CSC) Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-20838
MEDIUM 5.5
Local
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. |
|
CVE-2026-20835
MEDIUM 5.5
Local
Out-of-bounds read in Capability Access Management Service (camsvc) allows an authorized attacker to disclose information locally. |
|
CVE-2026-20834
MEDIUM 4.6
Physique
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. |
|
CVE-2026-20829
MEDIUM 5.5
Local
Out-of-bounds read in Windows TPM allows an authorized attacker to disclose information locally. |
|
CVE-2026-20828
MEDIUM 4.6
Physique
Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. |
|
CVE-2026-20827
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Tablet Windows User Interface (TWINUI) Subsystem allows an authorized attacker to disclose inform… |
|
CVE-2026-20825
MEDIUM 4.4
Local
Improper access control in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-20824
MEDIUM 5.5
Local
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. |
|
CVE-2026-20823
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally. |
|
CVE-2026-20821
MEDIUM 6.2
Local
Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-20819
MEDIUM 5.5
Local
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to disclose information locally. |
|
CVE-2026-20812
MEDIUM 6.5
Réseau
Improper input validation in Windows LDAP - Lightweight Directory Access Protocol allows an authorized attacker to perform tampering over a network. |
|
CVE-2026-20805
MEDIUM 5.5
KEV
Local
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally. |
|
CVE-2026-0890
MEDIUM 5.4
Réseau 1 apps
Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunder… |
|
CVE-2026-0888
MEDIUM 5.3
Réseau 1 apps
Information disclosure in the XML component. This vulnerability was fixed in Firefox 147 and Thunderbird 147. |
|
CVE-2026-0887
MEDIUM 4.3
Réseau 1 apps
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Th… |
|
CVE-2026-0886
MEDIUM 5.3
Réseau 1 apps
Incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, a… |
|
CVE-2026-0885
MEDIUM 6.5
Réseau 1 apps
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2026-0883
MEDIUM 5.3
Réseau 1 apps
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7. |
|
CVE-2025-14331
MEDIUM 6.5
Réseau 1 apps
Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 14… |
|
CVE-2025-12084
MEDIUM 5.3
Réseau 1 apps
When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail… |
|
CVE-2025-13836
MEDIUM 7.5
Réseau 1 apps
When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server… |
|
CVE-2025-52331
MEDIUM 6.1
Réseau 1 apps
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the … |
|
CVE-2025-6075
MEDIUM 5.5
Local 1 apps
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables. |
|
CVE-2025-11716
MEDIUM 6.5
Réseau 1 apps
Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu… |
|
CVE-2025-11712
MEDIUM 6.1
Réseau 1 apps
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a… |
|
CVE-2025-11711
MEDIUM 6.5
Réseau 1 apps
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo… |
|
CVE-2025-59502
MEDIUM 7.5
Remote Procedure Call Denial of Service Vulnerability |
|
CVE-2025-10536
MEDIUM 6.2
Local 1 apps
Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140… |
|
CVE-2025-10532
MEDIUM 6.5
Réseau 1 apps
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird… |
|
CVE-2025-10531
MEDIUM 5.4
Réseau 1 apps
Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
|
CVE-2025-10529
MEDIUM 6.5
Réseau 1 apps
Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3. |
|
CVE-2025-9181
MEDIUM 6.5
Réseau 1 apps
Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T… |
|
CVE-2025-53779
MEDIUM 7.2
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2025-8033
MEDIUM 6.5
Réseau 1 apps
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in… |
|
CVE-2025-8027
MEDIUM 6.5
Réseau 1 apps
On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner… |
|
CVE-2025-49464
MEDIUM 6.5
Réseau 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access. |
|
CVE-2025-46789
MEDIUM 6.5
Réseau 1 apps
Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access. |
|
CVE-2025-49760
MEDIUM 3.5
Windows Storage Spoofing Vulnerability |
|
CVE-2025-5986
MEDIUM 6.5
Réseau 1 apps
A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti… |
|
CVE-2025-2884
MEDIUM 6.6
Local
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with… |
|
CVE-2025-3932
MEDIUM 6.5
Réseau 1 apps
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse… |
|
CVE-2025-4092
MEDIUM 6.5
Réseau 1 apps
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s… |
|
CVE-2025-4089
MEDIUM 5.1
Local 1 apps
Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t… |