Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

553 CVE touchent une app ou un OS suivi (Modéré, Android). 4 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
553
Activement exploitées
4
Fenêtre de publication
2016-05-09 → 2026-09-08

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

553 entrées Modéré Android Tout effacer
CVE
CVE-2026-55256
MEDIUM 6.5

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of s…

CVE-2026-45527
MEDIUM 4.3

In convertCleanApertureToRect of HeifCleanAperture.cpp, there is a possible way to cause a temporary denial of service due to an integer overflow. This could l…

CVE-2026-28633
MEDIUM 5.5

In initForUserNoTracing of VoiceInteractionManagerService.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to…

CVE-2026-28627
MEDIUM 4.3

In btm_sec_encrypt_change of btm_sec.cc, there is a possible downgrade attack due to a logic error in the code. This could lead to remote information disclosur…

CVE-2026-28617
MEDIUM 5.5

In add of WifiNetworkSuggestionsManager.java, there is a possible persistent DOS due to resource exhaustion. This could lead to local denial of service with no…

CVE-2026-28596
MEDIUM 5.5

In parseInterventionFromXml of GameManagerService.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local de…

CVE-2026-28584
MEDIUM 5.5

In createSessionInternal of PackageInstallerService.java, there is a possible way to permanently DoS the device due to a logic error in the code. This could le…

CVE-2026-12387
MEDIUM 5.1

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-12285
MEDIUM 4.0

Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows…

CVE-2026-62828
MEDIUM 5.4

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

CVE-2026-28581
MEDIUM 4.0

In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lea…

CVE-2026-28578
MEDIUM 5.5

In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to loca…

CVE-2026-0086
MEDIUM 6.8

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalati…

CVE-2026-0085
MEDIUM 5.5

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to …

CVE-2026-0080
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0079
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local deni…

CVE-2026-0075
MEDIUM 5.9

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no…

CVE-2026-0074
MEDIUM 5.5

In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of s…

CVE-2026-0070
MEDIUM 5.5

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This coul…

CVE-2026-0069
MEDIUM 5.5

In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with n…

CVE-2026-0067
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This coul…

CVE-2026-0061
MEDIUM 5.9

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could l…

CVE-2026-0060
MEDIUM 5.5

In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lea…

CVE-2026-0055
MEDIUM 6.2

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a pat…

CVE-2026-0052
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0051
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remot…

CVE-2026-0048
MEDIUM 6.8

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local …

CVE-2026-0046
MEDIUM 6.2

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead …

CVE-2026-0044
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote…

CVE-2026-0043
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local esca…

CVE-2026-0042
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local deni…

CVE-2026-0041
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service …

CVE-2026-0040
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0039
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote den…

CVE-2026-0018
MEDIUM 5.5

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead t…

CVE-2025-48648
MEDIUM 5.5

In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with…

CVE-2026-34193
MEDIUM 4.3

Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU…

CVE-2026-20454
MEDIUM 6.4

In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has alread…

CVE-2026-20453
MEDIUM 6.7

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has …

CVE-2026-35429
MEDIUM 4.3

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net…

CVE-2026-23866
MEDIUM 4.3

Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26…

CVE-2026-33119
MEDIUM 5.4

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a net…

CVE-2026-20431
MEDIUM 6.5

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station con…

CVE-2026-0049
MEDIUM 6.2

In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of …

CVE-2025-48651
MEDIUM 5.5

In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead …

CVE-2025-64505
MEDIUM · éditeur

[Apple ImageIO] Processing a maliciously crafted file may lead to unexpected app termination

CVE-2026-26123
MEDIUM 5.5

Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.

CVE-2026-0014
MEDIUM 6.2

In isPackageNullOrSystem of AppOpsService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local den…

CVE-2026-0012
MEDIUM 6.2

In setHideSensitive of ExpandableNotificationRow.java, there is a possible contact name leak due due to a logic error in the code. This could lead to local inf…

CVE-2025-39946
MEDIUM · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa