Vulnérabilités
Vulnérabilités des apps suivies
778 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-6857
MEDIUM 5.3
Réseau 1 apps
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni… |
|
CVE-2023-50762
MEDIUM 4.3
Réseau 1 apps
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w… |
|
CVE-2023-50761
MEDIUM 4.3
Réseau 1 apps
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t… |
|
CVE-2023-49646
MEDIUM 6.4
Réseau 4 apps
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-6507
MEDIUM 6.1
Réseau adjacent 1 apps
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. … |
|
CVE-2023-6209
MEDIUM 6.5
Réseau 1 apps
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. T… |
|
CVE-2023-6206
MEDIUM 5.4
Réseau 1 apps
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact t… |
|
CVE-2023-6205
MEDIUM 6.5
Réseau 1 apps
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability… |
|
CVE-2023-6204
MEDIUM 6.5
Réseau 1 apps
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on t… |
|
CVE-2023-43582
MEDIUM 5.5
Réseau 4 apps
Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access. |
|
CVE-2023-39205
MEDIUM 4.3
Réseau 4 apps
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-39204
MEDIUM 4.3
Réseau 4 apps
Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access. |
|
CVE-2023-39203
MEDIUM 4.3
Réseau 1 apps
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disc… |
|
CVE-2023-39199
MEDIUM 4.9
Réseau 4 apps
Cryptographic issues with In-Meeting Chat for some Zoom clients may allow a privileged user to conduct an information disclosure via network access. |
|
CVE-2023-5732
MEDIUM 6.5
Réseau 1 apps
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affect… |
|
CVE-2023-5727
MEDIUM 6.5
Réseau 1 apps
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. … |
|
CVE-2023-5726
MEDIUM 4.3
Réseau 1 apps
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. … |
|
CVE-2023-5725
MEDIUM 4.3
Réseau 1 apps
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulner… |
|
CVE-2023-5721
MEDIUM 4.3
Réseau 1 apps
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This … |
|
CVE-2023-5171
MEDIUM 6.5
Réseau 1 apps
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent… |
|
CVE-2023-5169
MEDIUM 6.5
Réseau 1 apps
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable… |
|
CVE-2023-4581
MEDIUM 4.3
Réseau 1 apps
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot… |
|
CVE-2023-4580
MEDIUM 6.5
Réseau 1 apps
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability … |
|
CVE-2023-4578
MEDIUM 6.5
Réseau 1 apps
When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function coul… |
|
CVE-2023-4577
MEDIUM 6.5
Réseau 1 apps
When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could pot… |
|
CVE-2023-4575
MEDIUM 6.5
Réseau 1 apps
When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simul… |
|
CVE-2023-4574
MEDIUM 6.5
Réseau 1 apps
When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simu… |
|
CVE-2023-4573
MEDIUM 6.5
Réseau 1 apps
When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exp… |
|
CVE-2023-40217
MEDIUM 5.3
Réseau 1 apps
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HT… |
|
CVE-2022-48566
MEDIUM 5.9
Réseau 1 apps
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variab… |
|
CVE-2022-48564
MEDIUM 6.5
Réseau 1 apps
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property Li… |
|
CVE-2023-38898
MEDIUM 5.3
Réseau 1 apps
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by th… |
|
CVE-2023-39209
MEDIUM 5.9
Réseau 1 apps
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network acce… |
|
CVE-2023-39218
MEDIUM 6.1
Réseau 4 apps
Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow a privileged user to enable information disclosure via network access. |
|
CVE-2023-38254
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36914
MEDIUM 5.5
Local
Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability |
|
CVE-2023-36913
MEDIUM 6.5
Réseau
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2023-36909
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-36908
MEDIUM 6.5
Réseau adjacent
Windows Hyper-V Information Disclosure Vulnerability |
|
CVE-2023-36907
MEDIUM 5.5
Local
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36906
MEDIUM 5.5
Local
Windows Cryptographic Services Information Disclosure Vulnerability |
|
CVE-2023-36905
MEDIUM 5.5
Local
Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability |
|
CVE-2023-36889
MEDIUM 5.5
Local
Windows Group Policy Security Feature Bypass Vulnerability |
|
CVE-2023-36532
MEDIUM 5.9
Réseau 4 apps
Buffer overflow in Zoom Clients before 5.14.5 may allow an unauthenticated user to enable a denial of service via network access. |
|
CVE-2023-35384
MEDIUM 5.4
Réseau
Windows HTML Platforms Security Feature Bypass Vulnerability |
|
CVE-2023-35377
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-35376
MEDIUM 6.5
Réseau
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability |
|
CVE-2023-37207
MEDIUM 6.5
Réseau 1 apps
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have le… |
|
CVE-2023-36539
MEDIUM 5.3
Réseau 4 apps
Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. |
|
CVE-2023-29545
MEDIUM 6.5
Réseau 1 apps
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the c… |