Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-20660
HIGH 6.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2024-20658
HIGH 7.8
Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability |
|
CVE-2024-20657
HIGH 7.0
Windows Group Policy Elevation of Privilege Vulnerability |
|
CVE-2024-20655
HIGH 6.6
Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability |
|
CVE-2024-20654
HIGH 8.0
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2024-20653
HIGH 7.8
Microsoft Common Log File System Elevation of Privilege Vulnerability |
|
CVE-2024-20652
HIGH 8.1
Windows HTML Platforms Security Feature Bypass Vulnerability |
|
CVE-2023-6864
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-6863
HIGH 8.8
Réseau 1 apps
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnera… |
|
CVE-2023-6862
HIGH 8.8
Réseau 1 apps
A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 1… |
|
CVE-2023-6861
HIGH 8.8
Réseau 1 apps
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6… |
|
CVE-2023-6860
MEDIUM 6.5
Réseau 1 apps
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe… |
|
CVE-2023-6859
HIGH 8.8
Réseau 1 apps
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Fi… |
|
CVE-2023-6858
HIGH 8.8
Réseau 1 apps
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunder… |
|
CVE-2023-6857
MEDIUM 5.3
Réseau 1 apps
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni… |
|
CVE-2023-6856
HIGH 8.8
Réseau 1 apps
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an att… |
|
CVE-2023-50762
MEDIUM 4.3
Réseau 1 apps
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w… |
|
CVE-2023-50761
MEDIUM 4.3
Réseau 1 apps
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t… |
|
CVE-2023-49646
MEDIUM 6.4
Réseau 4 apps
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-43586
HIGH 7.3
Réseau 1 apps
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalat… |
|
CVE-2023-36696
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36391
HIGH 7.8
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
|
CVE-2023-36012
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-36011
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36006
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36005
HIGH 7.5
Windows Telephony Server Elevation of Privilege Vulnerability |
|
CVE-2023-36004
HIGH 7.5
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability |
|
CVE-2023-36003
HIGH 6.7
XAML Diagnostics Elevation of Privilege Vulnerability |
|
CVE-2023-35644
HIGH 7.8
Windows Sysmain Service Elevation of Privilege Vulnerability |
|
CVE-2023-35643
HIGH 7.5
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-35642
HIGH 6.5
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2023-35641
CRITICAL 8.8
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35639
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2023-35638
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2023-35635
HIGH 5.5
Windows Kernel Denial of Service Vulnerability |
|
CVE-2023-35634
HIGH 8.0
Windows Bluetooth Driver Remote Code Execution Vulnerability |
|
CVE-2023-35632
HIGH 7.8
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2023-35631
HIGH 7.8
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-35630
CRITICAL 8.8
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35628
CRITICAL 8.1
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2023-35622
HIGH 7.5
Windows DNS Spoofing Vulnerability |
|
CVE-2023-21740
HIGH 7.8
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-20588
HIGH
AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice |
|
CVE-2023-6507
MEDIUM 6.1
Réseau adjacent 1 apps
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. … |
|
CVE-2023-6212
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-6209
MEDIUM 6.5
Réseau 1 apps
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. T… |
|
CVE-2023-6208
HIGH 8.8
Réseau 1 apps
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboa… |
|
CVE-2023-6207
HIGH 8.8
Réseau 1 apps
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. |
|
CVE-2023-6206
MEDIUM 5.4
Réseau 1 apps
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact t… |
|
CVE-2023-6205
MEDIUM 6.5
Réseau 1 apps
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability… |