Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-6204
MEDIUM 6.5
Réseau 1 apps
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on t… |
|
CVE-2023-43588
LOW 3.5
Réseau 2 apps
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access. |
|
CVE-2023-43582
MEDIUM 5.5
Réseau 4 apps
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
|
CVE-2023-39206
LOW 3.7
Réseau 4 apps
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-39205
MEDIUM 4.3
Réseau 4 apps
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-39204
MEDIUM 4.3
Réseau 4 apps
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-39203
MEDIUM 4.3
Réseau 1 apps
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disc… |
|
CVE-2023-39199
MEDIUM 4.9
Réseau 4 apps
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. |
|
CVE-2023-36719
HIGH 7.8
Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability |
|
CVE-2023-36705
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2023-36428
HIGH 5.5
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability |
|
CVE-2023-36427
HIGH 7.0
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36425
HIGH 8.0
Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
|
CVE-2023-36424
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36423
HIGH 8.8
Microsoft Remote Registry Service Remote Code Execution Vulnerability |
|
CVE-2023-36408
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36407
HIGH 7.8
Windows Hyper-V Elevation of Privilege Vulnerability |
|
CVE-2023-36406
HIGH 5.5
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2023-36405
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36404
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-36403
HIGH 7.0
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36402
HIGH 8.8
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36401
HIGH 7.2
Microsoft Remote Registry Service Remote Code Execution Vulnerability |
|
CVE-2023-36400
CRITICAL 8.8
Windows HMAC Key Derivation Elevation of Privilege Vulnerability |
|
CVE-2023-36399
HIGH 7.1
Windows Storage Elevation of Privilege Vulnerability |
|
CVE-2023-36398
HIGH 6.5
Windows NTFS Information Disclosure Vulnerability |
|
CVE-2023-36397
CRITICAL 9.8
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-36396
HIGH 7.8
Windows Compressed Folder Remote Code Execution Vulnerability |
|
CVE-2023-36395
HIGH 7.5
Windows Deployment Services Denial of Service Vulnerability |
|
CVE-2023-36394
HIGH 7.0
Windows Search Service Elevation of Privilege Vulnerability |
|
CVE-2023-36393
HIGH 7.8
Windows User Interface Application Core Remote Code Execution Vulnerability |
|
CVE-2023-36392
HIGH 7.5
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2023-36047
HIGH 7.8
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2023-36046
HIGH 7.1
Windows Authentication Denial of Service Vulnerability |
|
CVE-2023-36036
HIGH 7.8
KEV
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36033
HIGH 7.8
KEV
Windows DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2023-36028
HIGH 9.8
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability |
|
CVE-2023-36025
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-36017
HIGH 8.8
Windows Scripting Engine Memory Corruption Vulnerability |
|
CVE-2023-31102
HIGH 7.8
Local 1 apps
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. |
|
CVE-2023-5732
MEDIUM 6.5
Réseau 1 apps
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affect… |
|
CVE-2023-5730
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-5728
HIGH 7.5
Réseau 1 apps
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerab… |
|
CVE-2023-5727
MEDIUM 6.5
Réseau 1 apps
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. … |
|
CVE-2023-5726
MEDIUM 4.3
Réseau 1 apps
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. … |
|
CVE-2023-5725
MEDIUM 4.3
Réseau 1 apps
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner… |
|
CVE-2023-5724
HIGH 7.5
Réseau 1 apps
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119… |
|
CVE-2023-5721
MEDIUM 4.3
Réseau 1 apps
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This … |
|
CVE-2023-44487
HIGH 7.5
KEV
Réseau
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the w… |
|
CVE-2023-41774
CRITICAL 8.1
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability |