Aller au contenu
Appaloosa Scout

Vulnérabilités

Vulnérabilités des apps suivies

777 entrées

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

CVE
CVE-2024-30069
MEDIUM 4.7 Local

Windows Remote Access Connection Manager Information Disclosure Vulnerability

CVE-2024-30067
MEDIUM 5.5 Local

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30066
MEDIUM 5.5 Local

Winlogon Elevation of Privilege Vulnerability

CVE-2024-30065
MEDIUM 5.5 Local

Windows Themes Denial of Service Vulnerability

CVE-2024-30063
MEDIUM 6.7 Réseau adjacent

Windows Distributed File System (DFS) Remote Code Execution Vulnerability

CVE-2024-5693
MEDIUM 6.1 Réseau 1 apps

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. T…

CVE-2024-5692
MEDIUM 6.5 Réseau 1 apps

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.ur…

CVE-2024-5691
MEDIUM 4.7 Réseau 1 apps

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions…

CVE-2024-5690
MEDIUM 4.3 Réseau 1 apps

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulner…

CVE-2024-4769
MEDIUM 5.9 Réseau 1 apps

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses…

CVE-2024-4768
MEDIUM 6.1 Réseau 1 apps

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Fi…

CVE-2024-4767
MEDIUM 4.3 Réseau 1 apps

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disa…

CVE-2024-30050
MEDIUM 5.4

Windows Mark of the Web Security Feature Bypass Vulnerability

CVE-2024-3861
MEDIUM 4.0 Local 1 apps

If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability…

CVE-2024-3859
MEDIUM 5.9 Réseau 1 apps

On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulner…

CVE-2024-24694
MEDIUM 5.9 Local 1 apps

Improper privilege management in the installer for Zoom Desktop Client for Windows before version 5.17.10 may allow an authenticated user to conduct an escalat…

CVE-2024-30370
MEDIUM 4.3 Réseau 1 apps

RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The-Web protection mechanism on affected i…

CVE-2024-2611
MEDIUM 5.5 Réseau 1 apps

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox…

CVE-2024-2610
MEDIUM 6.1 Réseau 1 apps

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a…

CVE-2024-2609
MEDIUM 6.1 Réseau 1 apps

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi…

CVE-2024-2605
MEDIUM 5.9 Réseau 1 apps

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows …

CVE-2023-5388
MEDIUM 6.5 Réseau 1 apps

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data…

CVE-2024-1551
MEDIUM 6.1 Réseau 1 apps

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well …

CVE-2024-1550
MEDIUM 6.1 Réseau 1 apps

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedl…

CVE-2024-1549
MEDIUM 6.1 Réseau 1 apps

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and un…

CVE-2024-1548
MEDIUM 4.3 Réseau 1 apps

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing…

CVE-2024-1547
MEDIUM 6.5 Réseau 1 apps

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL sh…

CVE-2024-24699
MEDIUM 6.5 Réseau 4 apps

Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access.

CVE-2024-24698
MEDIUM 4.9 Réseau 4 apps

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVE-2024-24696
MEDIUM 6.8 Réseau 1 apps

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to …

CVE-2024-24695
MEDIUM 6.8 Réseau 1 apps

Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to …

CVE-2024-24690
MEDIUM 5.4 Réseau 4 apps

Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2024-21377
MEDIUM 5.5 Local

Windows DNS Information Disclosure Vulnerability

CVE-2024-21362
MEDIUM 5.5 Local

Windows Kernel Security Feature Bypass Vulnerability

CVE-2024-21356
MEDIUM 6.5 Réseau

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

CVE-2024-21344
MEDIUM 5.9 Réseau

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21343
MEDIUM 5.9 Réseau

Windows Network Address Translation (NAT) Denial of Service Vulnerability

CVE-2024-21341
MEDIUM 6.8 Physique

Windows Kernel Remote Code Execution Vulnerability

CVE-2024-21340
MEDIUM 4.6 Physique

Windows Kernel Information Disclosure Vulnerability

CVE-2024-21339
MEDIUM 6.4 Physique

Windows USB Generic Parent Driver Remote Code Execution Vulnerability

CVE-2024-21304
MEDIUM 4.1 Local

Trusted Compute Base Elevation of Privilege Vulnerability

CVE-2024-20684
MEDIUM 6.5 Local

Windows Hyper-V Denial of Service Vulnerability

CVE-2024-0753
MEDIUM 6.5 Réseau 1 apps

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunder…

CVE-2024-0749
MEDIUM 4.3 Réseau 1 apps

A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firef…

CVE-2024-0747
MEDIUM 6.5 Réseau 1 apps

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy…

CVE-2024-0746
MEDIUM 6.5 Réseau 1 apps

A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunde…

CVE-2024-0742
MEDIUM 4.3 Réseau 1 apps

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent …

CVE-2024-0741
MEDIUM 6.5 Réseau 1 apps

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox…

CVE-2023-6860
MEDIUM 6.5 Réseau 1 apps

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe…

CVE-2023-6857
MEDIUM 5.3 Réseau 1 apps

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni…