Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-30090
HIGH 7.0
Local
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2024-30089
HIGH 7.8
Local
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2024-30088
HIGH 7.0
KEV
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-30087
HIGH 7.8
Local
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-30086
HIGH 7.8
Local
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-30085
HIGH 7.8
Local
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30084
HIGH 7.0
Local
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability |
|
CVE-2024-30083
HIGH 7.5
Réseau
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-30082
HIGH 7.8
Local
Win32k Elevation of Privilege Vulnerability |
|
CVE-2024-30080
CRITICAL 9.8
Réseau
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2024-30078
HIGH 8.8
Réseau adjacent
Windows Wi-Fi Driver Remote Code Execution Vulnerability |
|
CVE-2024-30077
HIGH 8.0
Réseau
Windows OLE Remote Code Execution Vulnerability |
|
CVE-2024-30076
MEDIUM 6.8
Réseau
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2024-30072
HIGH 7.8
Local
Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability |
|
CVE-2024-30070
HIGH 7.5
Réseau
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2024-30069
MEDIUM 4.7
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30068
HIGH 8.8
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2024-30067
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30066
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30065
MEDIUM 5.5
Local
Windows Themes Denial of Service Vulnerability |
|
CVE-2024-30063
MEDIUM 6.7
Réseau adjacent
Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
|
CVE-2024-30062
HIGH 7.8
Local
Windows Standards-Based Storage Management Service Remote Code Execution Vulnerability |
|
CVE-2024-5702
HIGH 7.5
Réseau 1 apps
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, an… |
|
CVE-2024-5700
HIGH 7.0
Local 1 apps
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-5696
HIGH 8.6
Réseau 1 apps
By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability… |
|
CVE-2024-5693
MEDIUM 6.1
Réseau 1 apps
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T… |
|
CVE-2024-5692
MEDIUM 6.5
Réseau 1 apps
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur… |
|
CVE-2024-5691
MEDIUM 4.7
Réseau 1 apps
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions… |
|
CVE-2024-5690
MEDIUM 4.3
Réseau 1 apps
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner… |
|
CVE-2024-5688
HIGH 8.1
Réseau 1 apps
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 12… |
|
CVE-2024-30064
HIGH 8.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-50868
HIGH 7.5
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU |
|
CVE-2024-36052
HIGH 7.5
Réseau 1 apps
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. |
|
CVE-2024-32465
HIGH 7.3
Physique 1 apps
Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-loc… |
|
CVE-2024-32021
LOW 3.9
Local 1 apps
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that con… |
|
CVE-2024-32020
LOW 3.9
Local 1 apps
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into … |
|
CVE-2024-32004
HIGH 8.1
Local 1 apps
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in s… |
|
CVE-2024-4777
HIGH 7.5
Réseau 1 apps
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2024-4770
HIGH 8.8
Réseau 1 apps
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.… |
|
CVE-2024-4769
MEDIUM 5.9
Réseau 1 apps
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses… |
|
CVE-2024-4768
MEDIUM 6.1
Réseau 1 apps
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi… |
|
CVE-2024-4767
MEDIUM 4.3
Réseau 1 apps
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa… |
|
CVE-2024-4367
HIGH 8.8
Réseau 1 apps
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Fire… |
|
CVE-2024-27793
HIGH 7.8
Local 1 apps
The issue was addressed with improved checks. This issue is fixed in iTunes 12.13.2 for Windows. Parsing a file may lead to an unexpected app termination or ar… |
|
CVE-2024-30051
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2024-30050
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-30049
HIGH 7.8
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability |
|
CVE-2024-30040
HIGH 8.8
KEV
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2024-30039
HIGH 5.5
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30038
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |