Vulnérabilités
Vulnérabilités des apps suivies
773 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-11706
MEDIUM 6.5
Réseau 1 apps
A null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when handling malformed o… |
|
CVE-2024-11701
MEDIUM 4.3
Réseau 1 apps
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible sp… |
|
CVE-2024-11696
MEDIUM 5.4
Réseau 1 apps
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an i… |
|
CVE-2024-11695
MEDIUM 5.4
Réseau 1 apps
A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This … |
|
CVE-2024-11694
MEDIUM 6.1
Réseau 1 apps
Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the W… |
|
CVE-2024-11692
MEDIUM 4.3
Réseau 1 apps
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability… |
|
CVE-2024-11612
MEDIUM 6.5
Réseau 1 apps
7-Zip CopyCoder Infinite Loop Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected i… |
|
CVE-2024-11159
MEDIUM 4.3
Réseau 1 apps
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < … |
|
CVE-2024-10468
MEDIUM 5.3
Réseau 1 apps
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 13… |
|
CVE-2024-10465
MEDIUM 6.5
Réseau 1 apps
A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbir… |
|
CVE-2024-10464
MEDIUM 6.5
Réseau 1 apps
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing r… |
|
CVE-2024-10463
MEDIUM 6.5
Réseau 1 apps
Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Th… |
|
CVE-2024-10462
MEDIUM 6.5
Réseau 1 apps
Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird … |
|
CVE-2024-10461
MEDIUM 6.1
Réseau 1 apps
In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could al… |
|
CVE-2024-10460
MEDIUM 5.3
Réseau 1 apps
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Fire… |
|
CVE-2024-9287
MEDIUM 7.8
Local 1 apps
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, all… |
|
CVE-2024-44157
MEDIUM 5.5
Local 1 apps
A stack buffer overflow was addressed through improved input validation. This issue is fixed in Apple TV 1.5.0.152 for Windows, iTunes 12.13.3 for Windows. Par… |
|
CVE-2024-43573
MEDIUM 6.5
KEV
Windows MSHTML Platform Spoofing Vulnerability |
|
CVE-2024-9398
MEDIUM 5.3
Réseau 1 apps
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that … |
|
CVE-2024-9397
MEDIUM 6.1
Réseau 1 apps
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerabilit… |
|
CVE-2024-43487
MEDIUM 6.5
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-38258
MEDIUM 6.5
Réseau
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
|
CVE-2024-38256
MEDIUM 5.5
Local
Windows Kernel-Mode Driver Information Disclosure Vulnerability |
|
CVE-2024-38254
MEDIUM 5.5
Local
Windows Authentication Information Disclosure Vulnerability |
|
CVE-2024-38235
MEDIUM 6.5
Local
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-38234
MEDIUM 6.5
Réseau adjacent
Windows Networking Denial of Service Vulnerability |
|
CVE-2024-38231
MEDIUM 6.5
Réseau
Windows Remote Desktop Licensing Service Denial of Service Vulnerability |
|
CVE-2024-38230
MEDIUM 6.5
Réseau
Windows Standards-Based Storage Management Service Denial of Service Vulnerability |
|
CVE-2024-38217
MEDIUM 5.4
KEV
Réseau
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-8394
MEDIUM 6.5
Réseau 1 apps
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vuln… |
|
CVE-2024-38213
MEDIUM 6.5
KEV
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-7529
MEDIUM 6.5
Réseau 1 apps
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability … |
|
CVE-2024-7526
MEDIUM 7.5
Réseau 1 apps
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnera… |
|
CVE-2024-7518
MEDIUM 6.5
Réseau 1 apps
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affect… |
|
CVE-2024-6614
MEDIUM 4.3
Réseau 1 apps
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6613
MEDIUM 5.5
Local 1 apps
The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 … |
|
CVE-2024-6612
MEDIUM 5.3
Réseau 1 apps
CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CS… |
|
CVE-2024-6610
MEDIUM 4.3
Réseau 1 apps
Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen m… |
|
CVE-2024-6608
MEDIUM 4.3
Réseau 1 apps
It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulner… |
|
CVE-2024-6603
MEDIUM 7.4
Réseau 1 apps
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerabilit… |
|
CVE-2024-6601
MEDIUM 4.7
Réseau 1 apps
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < … |
|
CVE-2024-6600
MEDIUM 6.3
Réseau 1 apps
Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private s… |
|
CVE-2024-39684
MEDIUM 7.8
Github: CVE-2024-39684 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-38517
MEDIUM 7.8
Github: CVE-2024-38517 TenCent RapidJSON Elevation of Privilege Vulnerability |
|
CVE-2024-30096
MEDIUM 5.5
Local
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2024-30076
MEDIUM 6.8
Réseau
Windows Container Manager Service Elevation of Privilege Vulnerability |
|
CVE-2024-30069
MEDIUM 4.7
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30067
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30066
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30065
MEDIUM 5.5
Local
Windows Themes Denial of Service Vulnerability |