Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-37976
HIGH 6.7
Windows Resume Extensible Firmware Interface Security Feature Bypass Vulnerability |
|
CVE-2024-30092
HIGH 8.0
Windows Hyper-V Remote Code Execution Vulnerability |
|
CVE-2024-20659
HIGH 7.1
Windows Hyper-V Security Feature Bypass Vulnerability |
|
CVE-2024-44193
HIGH 7.8
Local 1 apps
A logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to elevate their privil… |
|
CVE-2024-9403
HIGH 7.3
Réseau 1 apps
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could h… |
|
CVE-2024-9402
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2024-9401
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptio… |
|
CVE-2024-9400
HIGH 8.8
Réseau 1 apps
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. Th… |
|
CVE-2024-9399
HIGH 7.5
Réseau 1 apps
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulner… |
|
CVE-2024-9398
MEDIUM 5.3
Réseau 1 apps
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that … |
|
CVE-2024-9397
MEDIUM 6.1
Réseau 1 apps
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerabilit… |
|
CVE-2024-9396
HIGH 8.8
Réseau 1 apps
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. T… |
|
CVE-2024-9394
HIGH 7.5
Réseau 1 apps
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to a… |
|
CVE-2024-9393
HIGH 7.5
Réseau 1 apps
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to acc… |
|
CVE-2024-9392
CRITICAL 9.8
Réseau 1 apps
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3… |
|
CVE-2024-43487
MEDIUM 6.5
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-43467
HIGH 7.5
Réseau
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-43461
HIGH 8.8
KEV
Réseau
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-43455
HIGH 8.8
Réseau
Windows Remote Desktop Licensing Service Spoofing Vulnerability |
|
CVE-2024-43454
HIGH 7.1
Réseau
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38263
HIGH 7.5
Réseau
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38260
HIGH 8.8
Réseau
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
|
CVE-2024-38259
HIGH 8.8
Réseau
Microsoft Management Console Remote Code Execution Vulnerability |
|
CVE-2024-38258
MEDIUM 6.5
Réseau
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
|
CVE-2024-38257
HIGH 7.5
Réseau
Microsoft AllJoyn API Information Disclosure Vulnerability |
|
CVE-2024-38256
MEDIUM 5.5
Local
Windows Kernel-Mode Driver Information Disclosure Vulnerability |
|
CVE-2024-38254
MEDIUM 5.5
Local
Windows Authentication Information Disclosure Vulnerability |
|
CVE-2024-38253
HIGH 7.8
Local
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-38252
HIGH 7.8
Local
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-38250
HIGH 7.8
Local
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38249
HIGH 7.8
Local
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38248
HIGH 7.0
Local
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2024-38247
HIGH 7.8
Local
Windows Graphics Component Elevation of Privilege Vulnerability |
|
CVE-2024-38246
HIGH 7.0
Local
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-38245
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38244
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38243
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38242
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38241
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38240
HIGH 8.1
Réseau
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2024-38239
HIGH 7.2
Réseau
Windows Kerberos Elevation of Privilege Vulnerability |
|
CVE-2024-38238
HIGH 7.8
Local
Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38237
HIGH 7.8
Local
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability |
|
CVE-2024-38236
HIGH 7.5
Réseau
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-38235
MEDIUM 6.5
Local
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-38234
MEDIUM 6.5
Réseau adjacent
Windows Networking Denial of Service Vulnerability |
|
CVE-2024-38231
MEDIUM 6.5
Réseau
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38230
MEDIUM 6.5
Réseau
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38119
HIGH 7.5
Réseau adjacent
Windows Network Address Translation (NAT) Remote Code Execution Vulnerability |