Vulnérabilités
Vulnérabilités des apps suivies
8 497 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-33155
HIGH 7.8
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-33154
HIGH 7.8
Windows Partition Management Driver Elevation of Privilege Vulnerability |
|
CVE-2023-32085
HIGH 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
|
CVE-2023-32084
HIGH 7.5
HTTP.sys Denial of Service Vulnerability |
|
CVE-2023-32083
HIGH 6.5
Microsoft Failover Cluster Information Disclosure Vulnerability |
|
CVE-2023-32057
CRITICAL 9.8
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
|
CVE-2023-32056
HIGH 7.8
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability |
|
CVE-2023-32055
HIGH 6.7
Active Template Library Elevation of Privilege Vulnerability |
|
CVE-2023-32054
HIGH 7.3
Volume Shadow Copy Elevation of Privilege Vulnerability |
|
CVE-2023-32053
HIGH 7.8
Windows Installer Elevation of Privilege Vulnerability |
|
CVE-2023-32049
HIGH 8.8
KEV
Windows SmartScreen Security Feature Bypass Vulnerability |
|
CVE-2023-32046
HIGH 7.8
KEV
Windows MSHTML Platform Elevation of Privilege Vulnerability |
|
CVE-2023-32045
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-32044
HIGH 7.5
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-32043
HIGH 6.8
Windows Remote Desktop Security Feature Bypass Vulnerability |
|
CVE-2023-32042
HIGH 6.5
OLE Automation Information Disclosure Vulnerability |
|
CVE-2023-32041
HIGH 5.5
Windows Update Orchestrator Service Information Disclosure Vulnerability |
|
CVE-2023-32040
HIGH 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
|
CVE-2023-32039
HIGH 5.5
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability |
|
CVE-2023-32038
HIGH 8.8
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2023-32037
HIGH 6.5
Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability |
|
CVE-2023-32035
HIGH 6.5
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-32034
HIGH 6.5
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-32033
HIGH 6.6
Microsoft Failover Cluster Remote Code Execution Vulnerability |
|
CVE-2023-21756
HIGH 7.8
Windows Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-21526
HIGH 7.4
Windows Netlogon Information Disclosure Vulnerability |
|
CVE-2023-37211
HIGH 8.8
Réseau 1 apps
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2023-37208
HIGH 7.8
Local 1 apps
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < … |
|
CVE-2023-37207
MEDIUM 6.5
Réseau 1 apps
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have le… |
|
CVE-2023-37202
HIGH 8.8
Réseau 1 apps
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-… |
|
CVE-2023-37201
HIGH 8.8
Réseau 1 apps
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR… |
|
CVE-2023-36539
MEDIUM 5.3
Réseau 4 apps
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-36632
HIGH 7.5
Réseau 1 apps
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling … |
|
CVE-2023-32353
HIGH 7.8
Local 1 apps
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges. |
|
CVE-2023-32351
HIGH 7.8
Local 1 apps
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to gain elevated privileges. |
|
CVE-2023-34416
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume t… |
|
CVE-2023-34414
LOW 3.1
Réseau 1 apps
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha… |
|
CVE-2023-29545
MEDIUM 6.5
Réseau 1 apps
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c… |
|
CVE-2023-29542
CRITICAL 9.8
Réseau 1 apps
A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .downlo… |
|
CVE-2023-32214
HIGH 7.5
Réseau 1 apps
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating… |
|
CVE-2023-29532
MEDIUM 5.5
Local 1 apps
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB s… |
|
CVE-2023-29531
CRITICAL 9.8
Réseau 1 apps
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug onl… |
|
CVE-2023-34114
HIGH 7.4
Réseau 2 apps
Exposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potentially enable infor… |
|
CVE-2023-34121
MEDIUM 4.1
Réseau 1 apps
Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially… |
|
CVE-2023-28602
LOW 2.8
Local 1 apps
Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade… |
|
CVE-2023-28601
HIGH 8.3
Réseau adjacent 1 apps
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user ma… |
|
CVE-2023-28599
MEDIUM 4.3
Réseau 4 apps
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could inject HTML into their display name potentially leading a victi… |
|
CVE-2023-32022
HIGH 7.6
Windows Server Service Security Feature Bypass Vulnerability |
|
CVE-2023-32021
HIGH 7.1
Windows SMB Witness Service Security Feature Bypass Vulnerability |
|
CVE-2023-32020
HIGH 5.6
Windows DNS Spoofing Vulnerability |