Vulnérabilités
Vulnérabilités des apps suivies
8 530 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2021-43233
CRITICAL 7.5
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2021-43232
HIGH 7.8
Windows Event Tracing Remote Code Execution Vulnerability |
|
CVE-2021-43231
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-43230
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-43229
HIGH 7.8
Windows NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-43228
HIGH 7.5
SymCrypt Denial of Service Vulnerability |
|
CVE-2021-43227
HIGH 5.5
Storage Spaces Controller Information Disclosure Vulnerability |
|
CVE-2021-43226
HIGH 7.8
KEV
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-43224
HIGH 5.5
Windows Common Log File System Driver Information Disclosure Vulnerability |
|
CVE-2021-43223
HIGH 7.8
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability |
|
CVE-2021-43222
HIGH 7.5
Microsoft Message Queuing Information Disclosure Vulnerability |
|
CVE-2021-43219
HIGH 7.4
DirectX Graphics Kernel File Denial of Service Vulnerability |
|
CVE-2021-43217
CRITICAL 8.1
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability |
|
CVE-2021-43216
HIGH 6.5
Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability |
|
CVE-2021-43215
CRITICAL 9.8
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution |
|
CVE-2021-43207
HIGH 7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2021-41333
HIGH 7.8
Windows Print Spooler Elevation of Privilege Vulnerability |
|
CVE-2021-43546
MEDIUM 4.3
Réseau 1 app
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefo… |
|
CVE-2021-43545
MEDIUM 6.5
Réseau 1 app
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0,… |
|
CVE-2021-43543
MEDIUM 6.1
Réseau 1 app
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects… |
|
CVE-2021-43542
MEDIUM 6.5
Réseau 1 app
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability aff… |
|
CVE-2021-43541
MEDIUM 6.5
Réseau 1 app
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunder… |
|
CVE-2021-43539
HIGH 8.8
Réseau 1 app
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers… |
|
CVE-2021-43538
MEDIUM 4.3
Réseau 1 app
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock… |
|
CVE-2021-43537
HIGH 8.8
Réseau 1 app
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulne… |
|
CVE-2021-43536
MEDIUM 6.5
Réseau 1 app
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < … |
|
CVE-2021-43535
HIGH 8.8
Réseau 1 app
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable… |
|
CVE-2021-43534
HIGH 8.8
Réseau 1 app
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory c… |
|
CVE-2021-43528
MEDIUM 6.5
Réseau 1 app
Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive chrome-level… |
|
CVE-2021-38510
HIGH 8.8
Réseau 1 app
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: Thi… |
|
CVE-2021-38509
MEDIUM 4.3
Réseau 1 app
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top a… |
|
CVE-2021-38508
MEDIUM 4.3
Réseau 1 app
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could hav… |
|
CVE-2021-38507
MEDIUM 6.5
Réseau 1 app
The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HT… |
|
CVE-2021-38506
MEDIUM 4.3
Réseau 1 app
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on… |
|
CVE-2021-38505
MEDIUM 6.5
Réseau 1 app
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it… |
|
CVE-2021-38504
HIGH 8.8
Réseau 1 app
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption a… |
|
CVE-2021-38503
CRITICAL 10.0
Réseau 1 app
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the … |
|
CVE-2021-42291
HIGH 7.5
Réseau
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42288
MEDIUM 5.7
Physique
Windows Hello Security Feature Bypass Vulnerability |
|
CVE-2021-42287
HIGH 7.5
KEV
Réseau
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42286
HIGH 7.8
Local
Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability |
|
CVE-2021-42285
HIGH 7.8
Local
Windows Kernel Elevation of Privilege Vulnerability |
|
CVE-2021-42284
MEDIUM 6.8
Réseau adjacent
Windows Hyper-V Denial of Service Vulnerability |
|
CVE-2021-42283
HIGH 8.8
Local
NTFS Elevation of Privilege Vulnerability |
|
CVE-2021-42282
HIGH 7.5
Réseau
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42280
MEDIUM 5.5
Local
Windows Feedback Hub Elevation of Privilege Vulnerability |
|
CVE-2021-42279
MEDIUM 4.2
Réseau
Chakra Scripting Engine Memory Corruption Vulnerability |
|
CVE-2021-42278
HIGH 7.5
KEV
Réseau
Active Directory Domain Services Elevation of Privilege Vulnerability |
|
CVE-2021-42277
MEDIUM 5.5
Local
Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability |
|
CVE-2021-42276
HIGH 7.8
Local
Microsoft Windows Media Foundation Remote Code Execution Vulnerability |