Vulnérabilités
Vulnérabilités des apps suivies
2 273 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2026-43663
MEDIUM 6.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visio… |
|
CVE-2026-39872
MEDIUM 6.5
Réseau
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visio… |
|
CVE-2026-28979
MEDIUM 6.5
Réseau
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5… |
|
CVE-2026-12330
MEDIUM 5.4
Réseau 1 apps
Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 14… |
|
CVE-2026-12329
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12. |
|
CVE-2026-12325
MEDIUM 6.5
Réseau 1 apps
Denial-of-service in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, an… |
|
CVE-2026-12323
MEDIUM 5.4
Réseau 1 apps
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12322
MEDIUM 5.4
Réseau 1 apps
Clickjacking issue in the Widget: Gtk component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12321
MEDIUM 5.4
Réseau 1 apps
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12320
MEDIUM 4.3
Réseau 1 apps
Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12319
MEDIUM 6.5
Réseau 1 apps
Denial-of-service in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12313
MEDIUM 4.7
Réseau 1 apps
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb… |
|
CVE-2026-12311
MEDIUM 4.7
Réseau 1 apps
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderb… |
|
CVE-2026-12309
MEDIUM 6.5
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12308
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12307
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12306
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-12303
MEDIUM 4.3
Réseau 1 apps
Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12302
MEDIUM 6.5
Réseau 1 apps
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thu… |
|
CVE-2026-12301
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12300
MEDIUM 5.3
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
|
CVE-2026-12299
MEDIUM 5.4
Réseau 1 apps
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and… |
|
CVE-2026-12298
MEDIUM 5.4
Réseau 1 apps
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. |
|
CVE-2026-50508
MEDIUM 6.5
Réseau
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. |
|
CVE-2026-50507
MEDIUM 6.8
Physique
Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-48566
MEDIUM 5.5
Local
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-45655
MEDIUM 5.3
Physique
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. |
|
CVE-2026-45634
MEDIUM 5.5
Local
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally. |
|
CVE-2026-45608
MEDIUM 6.8
Local
Out-of-bounds read in Windows DHCP Client allows an unauthorized attacker to disclose information locally. |
|
CVE-2026-45606
MEDIUM 5.5
Local
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally. |
|
CVE-2026-45604
MEDIUM 5.5
Local
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally. |
|
CVE-2026-45595
MEDIUM 5.4
Réseau
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network. |
|
CVE-2026-45594
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose informat… |
|
CVE-2026-44814
MEDIUM 5.5
Local
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally. |
|
CVE-2026-44805
MEDIUM 5.5
Local
Use after free in Windows Network Controller (NC) Host Agent allows an authorized attacker to deny service locally. |
|
CVE-2026-42973
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42972
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally. |
|
CVE-2026-42971
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42970
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42969
MEDIUM 5.5
Local
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally. |
|
CVE-2026-42968
MEDIUM 5.5
Local
Out-of-bounds read in Windows Telephony Service allows an authorized attacker to disclose information locally. |
|
CVE-2026-42915
MEDIUM 5.5
Local
Incorrect calculation of buffer size in Windows VMSwitch allows an authorized attacker to deny service locally. |
|
CVE-2026-42914
MEDIUM 5.3
Réseau
Out-of-bounds read in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-42907
MEDIUM 6.5
Réseau
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. |
|
CVE-2026-42906
MEDIUM 5.5
Local
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally. |
|
CVE-2026-42903
MEDIUM 6.5
Réseau
Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. |
|
CVE-2026-48112
MEDIUM 6.5
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF parser. A … |
|
CVE-2026-48111
MEDIUM 4.3
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedenc… |
|
CVE-2026-48104
MEDIUM 4.2
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused b… |
|
CVE-2026-48103
MEDIUM 4.3
Réseau 1 apps
7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) … |