Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-38141
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-38140
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-38139
HIGH 7.8
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2023-36805
HIGH 7.0
Windows MSHTML Platform Security Feature Bypass Vulnerability |
|
CVE-2023-36804
HIGH 7.8
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-36803
HIGH 5.5
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2023-36802
HIGH 7.8
KEV
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability |
|
CVE-2023-36801
HIGH 5.3
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-35355
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-4585
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-4584
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence… |
|
CVE-2023-4583
HIGH 7.5
Réseau 1 apps
When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been dis… |
|
CVE-2023-4582
HIGH 8.8
Réseau 1 apps
Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory… |
|
CVE-2023-4581
MEDIUM 4.3
Réseau 1 apps
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot… |
|
CVE-2023-4580
MEDIUM 6.5
Réseau 1 apps
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability … |
|
CVE-2023-4578
MEDIUM 6.5
Réseau 1 apps
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul… |
|
CVE-2023-4577
MEDIUM 6.5
Réseau 1 apps
When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot… |
|
CVE-2023-4576
HIGH 8.6
Réseau 1 apps
On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that… |
|
CVE-2023-4575
MEDIUM 6.5
Réseau 1 apps
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul… |
|
CVE-2023-4574
MEDIUM 6.5
Réseau 1 apps
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu… |
|
CVE-2023-4573
MEDIUM 6.5
Réseau 1 apps
When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp… |
|
CVE-2023-40217
MEDIUM 5.3
Réseau 1 apps
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT… |
|
CVE-2023-38831
HIGH 7.8
KEV
Local 1 apps
RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because … |
|
CVE-2023-41105
HIGH 7.5
Réseau 1 apps
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly… |
|
CVE-2022-48566
MEDIUM 5.9
Réseau 1 apps
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab… |
|
CVE-2022-48565
CRITICAL 9.8
Réseau 1 apps
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoi… |
|
CVE-2022-48564
MEDIUM 6.5
Réseau 1 apps
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li… |
|
CVE-2022-48560
HIGH 7.5
Réseau 1 apps
A use-after-free exists in Python through 3.9 via heappushpop in heapq. |
|
CVE-2023-38898
MEDIUM 5.3
Réseau 1 apps
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th… |
|
CVE-2023-39214
HIGH 7.6
Réseau 4 apps
Exposure of sensitive information in Zoom Client SDK's before 5.15.5 may allow an authenticated user to enable a denial of service via network access. |
|
CVE-2023-39213
CRITICAL 9.6
Réseau 1 apps
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI Client before 5.15.2 may allow an unauthenticated user to enable an… |
|
CVE-2023-39211
HIGH 8.8
Local 1 apps
Improper privilege management in Zoom Desktop Client for Windows and Zoom Rooms for Windows before 5.15.5 may allow an authenticated user to enable an informat… |
|
CVE-2023-39209
MEDIUM 5.9
Réseau 1 apps
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network acce… |
|
CVE-2023-39218
MEDIUM 6.1
Réseau 4 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-39216
CRITICAL 9.6
Réseau 1 apps
Improper input validation in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network a… |
|
CVE-2023-38254
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-38186
HIGH 8.8
Réseau
Windows Mobile Device Management Elevation of Privilege Vulnerability |
|
CVE-2023-38184
HIGH 7.5
Réseau
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability |
|
CVE-2023-38172
HIGH 7.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36914
MEDIUM 5.5
Local
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability |
|
CVE-2023-36913
MEDIUM 6.5
Réseau
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2023-36912
HIGH 7.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36911
CRITICAL 9.8
Réseau
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-36910
CRITICAL 9.8
Réseau
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-36909
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36908
MEDIUM 6.5
Réseau adjacent
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2023-36907
MEDIUM 5.5
Local
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36906
MEDIUM 5.5
Local
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36905
MEDIUM 5.5
Local
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
|
CVE-2023-36904
HIGH 7.8
Local
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |