Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

1 821 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2026-2760
CRITICAL 10.0 Réseau 1 apps

Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Fire…

CVE-2026-2759
CRITICAL 9.8 Réseau 1 apps

Incorrect boundary conditions in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderb…

CVE-2026-2758
CRITICAL 9.8 Réseau 1 apps

Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunde…

CVE-2026-2757
CRITICAL 9.8 Réseau 1 apps

Incorrect boundary conditions in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunder…

CVE-2026-20677
CRITICAL 9.0 Réseau

A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS S…

CVE-2026-0892
CRITICAL 9.8 Réseau 1 apps

Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2026-0884
CRITICAL 9.8 Réseau 1 apps

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

CVE-2026-0881
CRITICAL 10.0 Réseau 1 apps

Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

CVE-2026-0879
CRITICAL 9.8 Réseau 1 apps

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140…

CVE-2025-43526
CRITICAL 9.8 Réseau

This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac with Lockdown Mode enabled, web content o…

CVE-2025-43428
CRITICAL 9.8 Réseau

A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Photos in t…

CVE-2025-62557
CRITICAL 8.4 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-62554
CRITICAL 8.4 Local 1 apps

Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-14330
CRITICAL 9.8 Réseau 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 14…

CVE-2025-14326
CRITICAL 9.8 Réseau 1 apps

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

CVE-2025-14324
CRITICAL 9.8 Réseau 1 apps

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146…

CVE-2025-14321
CRITICAL 9.8 Réseau 1 apps

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

CVE-2025-48638
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-48624
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-48623
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-47372
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-47319
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-60724
CRITICAL 9.8 Réseau 1 apps

Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

CVE-2025-60716
CRITICAL 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2025-48593
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-59234
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-59227
CRITICAL 7.8 Local 1 apps

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-11721
CRITICAL 9.8 Réseau 1 apps

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could h…

CVE-2025-11719
CRITICAL 9.8 Réseau 1 apps

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.…

CVE-2025-11710
CRITICAL 9.8 Réseau 1 apps

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised proce…

CVE-2025-11709
CRITICAL 9.8 Réseau 1 apps

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

CVE-2025-11708
CRITICAL 9.8 Réseau 1 apps

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

CVE-2025-59287
CRITICAL 9.8 KEV

Windows Server Update Service (WSUS) Remote Code Execution Vulnerability

CVE-2025-49708
CRITICAL 9.9

Microsoft Graphics Component Elevation of Privilege Vulnerability

CVE-2025-43362
CRITICAL 9.8 Réseau

The issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An app may be able to monitor keystrokes w…

CVE-2025-43359
CRITICAL 9.8 Réseau

A logic issue was addressed with improved state management. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS So…

CVE-2025-43347
CRITICAL 9.8 Réseau

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An inp…

CVE-2025-43343
CRITICAL 9.8 Réseau

The issue was addressed with improved memory handling. This issue is fixed in Safari 26, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26…

CVE-2025-43342
CRITICAL 9.8 Réseau

A correctness issue was addressed with improved checks. This issue is fixed in Safari 26, iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS …

CVE-2025-31255
CRITICAL 9.8 Réseau

An authorization issue was addressed with improved state management. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS …

CVE-2025-53799
CRITICAL 5.5 Local 1 apps

Use of uninitialized resource in Windows Imaging Component allows an unauthorized attacker to disclose information locally.

CVE-2025-55236
CRITICAL 7.3

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-55228
CRITICAL 7.8

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2025-55226
CRITICAL 6.7

Graphics Kernel Remote Code Execution Vulnerability

CVE-2025-55224
CRITICAL 7.8

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2025-54918
CRITICAL 8.8

Windows NTLM Elevation of Privilege Vulnerability

CVE-2025-53800
CRITICAL 7.8

Windows Graphics Component Elevation of Privilege Vulnerability

CVE-2025-39682
CRITICAL 9.8 Réseau

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process …

CVE-2025-27034
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2025-21483
CRITICAL

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.