Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

33 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2026-50419
LOW 3.3 Local

Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.

CVE-2026-50416
LOW 3.3 Local

Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.

CVE-2026-58052
LOW 3.3 Local 1 apps

7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supp…

CVE-2026-45642
LOW 3.9 Physical

Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a…

CVE-2026-48102
LOW 3.1 Network 1 apps

7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image ha…

CVE-2026-4519
LOW 3.3 Local 1 apps

The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for certain web browsers. New behavior reject…

CVE-2025-13462
LOW 3.3 Local 1 apps

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME …

CVE-2025-13837
LOW 5.5 Local 1 apps

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

CVE-2025-55188
LOW 3.6 Local 1 apps

7-Zip before 25.01 does not always properly handle symbolic links during extraction.

CVE-2025-49462
LOW 3.5 Network 4 apps

Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVE-2025-49731
LOW 3.1 Network 2 apps

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVE-2022-47112
LOW 2.5 Local 1 apps

7-Zip 22.01 does not report an error for certain invalid xz files, involving stream flags and reserved bits. Some later versions are unaffected.

CVE-2022-47111
LOW 2.5 Local 1 apps

7-Zip 22.01 does not report an error for certain invalid xz files, involving block flags and reserved bits. Some later versions are unaffected.

CVE-2024-32021
LOW 3.9 Local 1 apps

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that con…

CVE-2024-32020
LOW 3.9 Local 1 apps

Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into …

CVE-2024-3302
LOW 3.7 Network 1 apps

There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the b…

CVE-2024-2616
LOW 2.7 Network 1 apps

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F…

CVE-2024-23743
LOW 3.3 Local 2 apps

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must lau…

CVE-2023-43588
LOW 3.5 Network 2 apps

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.

CVE-2023-39206
LOW 3.7 Network 4 apps

Buffer overflow in some Zoom clients may allow an unauthenticated user to conduct a denial of service via network access.

CVE-2023-38039
LOW

Hackerone: CVE-2023-38039 HTTP headers eat all memory

CVE-2023-34414
LOW 3.1 Network 1 apps

The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks tha…

CVE-2023-28602
LOW 2.8 Local 1 apps

Zoom for Windows clients prior to 5.13.5 contain an improper verification of cryptographic signature vulnerability. A malicious user may potentially downgrade…

CVE-2021-29948
LOW 2.5 Local 1 apps

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac…

CVE-2020-27895
LOW 3.3 Local 1 apps

An information disclosure issue existed in the transition of program state. This issue was addressed with improved state handling. This issue is fixed in iTune…

CVE-2020-17046
LOW 5.5

Windows Error Reporting Denial of Service Vulnerability

CVE-2019-1348
LOW 3.3 Local 1 apps

An issue was found in Git before v2.24.1, v2.23.1, v2.22.2, v2.21.1, v2.20.2, v2.19.3, v2.18.2, v2.17.3, v2.16.6, v2.15.4, and v2.14.6. The --export-marks opti…

CVE-2019-11743
LOW 3.7 Network 1 apps

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts …

CVE-2018-8136
LOW 6.5

Windows Remote Code Execution Vulnerability

CVE-2018-1000030
LOW 3.6 Local 1 apps

Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears t…

CVE-2016-0175
LOW 3.3 Local

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Window…

CVE-2015-1283
LOW 1 apps

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote …

CVE-2015-4000
LOW 3.7 Network 1 apps

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which…