Vulnérabilités
Vulnérabilités des apps suivies
777 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2024-30069
MEDIUM 4.7
Local
Windows Remote Access Connection Manager Information Disclosure Vulnerability |
|
CVE-2024-30067
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30066
MEDIUM 5.5
Local
Winlogon Elevation of Privilege Vulnerability |
|
CVE-2024-30065
MEDIUM 5.5
Local
Windows Themes Denial of Service Vulnerability |
|
CVE-2024-30063
MEDIUM 6.7
Réseau adjacent
Windows Distributed File System (DFS) Remote Code Execution Vulnerability |
|
CVE-2024-5693
MEDIUM 6.1
Réseau 1 apps
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T… |
|
CVE-2024-5692
MEDIUM 6.5
Réseau 1 apps
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur… |
|
CVE-2024-5691
MEDIUM 4.7
Réseau 1 apps
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions… |
|
CVE-2024-5690
MEDIUM 4.3
Réseau 1 apps
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner… |
|
CVE-2024-4769
MEDIUM 5.9
Réseau 1 apps
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses… |
|
CVE-2024-4768
MEDIUM 6.1
Réseau 1 apps
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi… |
|
CVE-2024-4767
MEDIUM 4.3
Réseau 1 apps
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa… |
|
CVE-2024-30050
MEDIUM 5.4
Windows Mark of the Web Security Feature Bypass Vulnerability |
|
CVE-2024-3861
MEDIUM 4.0
Local 1 apps
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability… |
|
CVE-2024-3859
MEDIUM 5.9
Réseau 1 apps
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulner… |
|
CVE-2024-24694
MEDIUM 5.9
Local 1 apps
Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalat… |
|
CVE-2024-30370
MEDIUM 4.3
Réseau 1 apps
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i… |
|
CVE-2024-2611
MEDIUM 5.5
Réseau 1 apps
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox… |
|
CVE-2024-2610
MEDIUM 6.1
Réseau 1 apps
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a… |
|
CVE-2024-2609
MEDIUM 6.1
Réseau 1 apps
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi… |
|
CVE-2024-2605
MEDIUM 5.9
Réseau 1 apps
An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows … |
|
CVE-2023-5388
MEDIUM 6.5
Réseau 1 apps
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data… |
|
CVE-2024-1551
MEDIUM 6.1
Réseau 1 apps
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well … |
|
CVE-2024-1550
MEDIUM 6.1
Réseau 1 apps
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl… |
|
CVE-2024-1549
MEDIUM 6.1
Réseau 1 apps
If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un… |
|
CVE-2024-1548
MEDIUM 4.3
Réseau 1 apps
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing… |
|
CVE-2024-1547
MEDIUM 6.5
Réseau 1 apps
Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh… |
|
CVE-2024-24699
MEDIUM 6.5
Réseau 4 apps
Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. |
|
CVE-2024-24698
MEDIUM 4.9
Réseau 4 apps
Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. |
|
CVE-2024-24696
MEDIUM 6.8
Réseau 1 apps
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to … |
|
CVE-2024-24695
MEDIUM 6.8
Réseau 1 apps
Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to … |
|
CVE-2024-24690
MEDIUM 5.4
Réseau 4 apps
Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2024-21377
MEDIUM 5.5
Local
Windows DNS Information Disclosure Vulnerability |
|
CVE-2024-21362
MEDIUM 5.5
Local
Windows Kernel Security Feature Bypass Vulnerability |
|
CVE-2024-21356
MEDIUM 6.5
Réseau
Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability |
|
CVE-2024-21344
MEDIUM 5.9
Réseau
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-21343
MEDIUM 5.9
Réseau
Windows Network Address Translation (NAT) Denial of Service Vulnerability |
|
CVE-2024-21341
MEDIUM 6.8
Physique
Windows Kernel Remote Code Execution Vulnerability |
|
CVE-2024-21340
MEDIUM 4.6
Physique
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2024-21339
MEDIUM 6.4
Physique
Windows USB Generic Parent Driver Remote Code Execution Vulnerability |
|
CVE-2024-21304
MEDIUM 4.1
Local
Trusted Compute Base Elevation of Privilege Vulnerability |
|
CVE-2024-20684
MEDIUM 6.5
Local
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2024-0753
MEDIUM 6.5
Réseau 1 apps
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunder… |
|
CVE-2024-0749
MEDIUM 4.3
Réseau 1 apps
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firef… |
|
CVE-2024-0747
MEDIUM 6.5
Réseau 1 apps
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy… |
|
CVE-2024-0746
MEDIUM 6.5
Réseau 1 apps
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde… |
|
CVE-2024-0742
MEDIUM 4.3
Réseau 1 apps
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent … |
|
CVE-2024-0741
MEDIUM 6.5
Réseau 1 apps
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox… |
|
CVE-2023-6860
MEDIUM 6.5
Réseau 1 apps
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe… |
|
CVE-2023-6857
MEDIUM 5.3
Réseau 1 apps
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni… |