Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

760 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2025-53779
MEDIUM 7.2

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-8033
MEDIUM 6.5 Network 1 apps

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in…

CVE-2025-8027
MEDIUM 6.5 Network 1 apps

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner…

CVE-2025-49464
MEDIUM 6.5 Network 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

CVE-2025-46789
MEDIUM 6.5 Network 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVE-2025-49760
MEDIUM 3.5

Windows Storage Spoofing Vulnerability

CVE-2025-5986
MEDIUM 6.5 Network 1 apps

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-2884
MEDIUM 6.6 Local

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-3932
MEDIUM 6.5 Network 1 apps

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-4092
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-4089
MEDIUM 5.1 Local 1 apps

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t…

CVE-2025-4088
MEDIUM 6.5 Network 1 apps

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo…

CVE-2025-4087
MEDIUM 4.8 Network 1 apps

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou…

CVE-2025-4084
MEDIUM 5.7 Network 1 apps

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi…

CVE-2025-4082
MEDIUM 5.9 Network 1 apps

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate…

CVE-2025-3523
MEDIUM 6.4 Network 1 apps

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove…

CVE-2025-3522
MEDIUM 6.3 Network 1 apps

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a…

CVE-2025-2830
MEDIUM 6.3 Network 1 apps

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t…

CVE-2025-31334
MEDIUM 6.8 Network 1 apps

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v…

CVE-2025-3031
MEDIUM 6.5 Network 1 apps

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

CVE-2025-3028
MEDIUM 6.5 Network 1 apps

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firef…

CVE-2025-26695
MEDIUM 5.3 Local 1 apps

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai…

CVE-2025-1938
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1935
MEDIUM 4.3 Network 1 apps

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR…

CVE-2025-1934
MEDIUM 6.5 Network 1 apps

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no…

CVE-2025-1019
MEDIUM 4.3 Network 1 apps

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. …

CVE-2025-1018
MEDIUM 5.3 Network 1 apps

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential sp…

CVE-2025-1015
MEDIUM 5.4 Network 1 apps

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malici…

CVE-2025-1013
MEDIUM 6.5 Network 1 apps

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vu…

CVE-2025-0510
MEDIUM 6.5 Network 1 apps

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vu…

CVE-2025-0243
MEDIUM 5.1 Local 1 apps

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption a…

CVE-2025-0242
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bug…

CVE-2025-0240
MEDIUM 4.0 Local 1 apps

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability w…

CVE-2025-0239
MEDIUM 4.0 Local 1 apps

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Fi…

CVE-2025-0238
MEDIUM 5.3 Network 1 apps

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability …

CVE-2025-0237
MEDIUM 5.4 Network 1 apps

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal bein…

CVE-2024-11708
MEDIUM 6.5 Network 1 apps

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an…

CVE-2024-11706
MEDIUM 6.5 Network 1 apps

A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed o…

CVE-2024-11701
MEDIUM 4.3 Network 1 apps

The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible sp…

CVE-2024-11696
MEDIUM 5.4 Network 1 apps

The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an i…

CVE-2024-11695
MEDIUM 5.4 Network 1 apps

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This …

CVE-2024-11694
MEDIUM 6.1 Network 1 apps

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the W…

CVE-2024-11692
MEDIUM 4.3 Network 1 apps

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability…

CVE-2024-11612
MEDIUM 6.5 Network 1 apps

7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected i…

CVE-2024-11159
MEDIUM 4.3 Network 1 apps

Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < …

CVE-2024-10468
MEDIUM 5.3 Network 1 apps

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13…

CVE-2024-10465
MEDIUM 6.5 Network 1 apps

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir…

CVE-2024-10464
MEDIUM 6.5 Network 1 apps

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r…

CVE-2024-10463
MEDIUM 6.5 Network 1 apps

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th…

CVE-2024-10462
MEDIUM 6.5 Network 1 apps

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird …