Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,495 CVEs affect a tracked app or OS (all severities, Windows). 214 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,495
Actively exploited
214
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,495 entries Windows Clear all
CVE
CVE-2019-9816
MEDIUM 5.9 1 app

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security ch…

CVE-2019-9815
HIGH 8.1 1 app

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to…

CVE-2019-9811
HIGH 8.3 1 app

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that …

CVE-2019-9800
CRITICAL 9.8 1 app

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed e…

CVE-2019-11730
MEDIUM 6.5 1 app

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directo…

CVE-2019-11729
HIGH 7.5 1 app

Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This …

CVE-2019-11719
HIGH 7.5 1 app

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Servic…

CVE-2019-11717
MEDIUM 5.3 1 app

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible …

CVE-2019-11715
MEDIUM 6.1 1 app

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certa…

CVE-2019-11713
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This…

CVE-2019-11712
HIGH 8.8 1 app

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to per…

CVE-2019-11711
HIGH 8.8 1 app

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperative…

CVE-2019-11709
CRITICAL 9.8 1 app

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory c…

CVE-2019-11708
CRITICAL 10.0 KEV 1 app

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process op…

CVE-2019-11707
HIGH 8.8 KEV 1 app

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware…

CVE-2019-11706
HIGH 7.5 1 app

A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain email messages, resulti…

CVE-2019-11705
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messages, resulting in …

CVE-2019-11704
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email messages, resulting…

CVE-2019-11703
CRITICAL 9.8 1 app

A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages, resulting in a pot…

CVE-2019-11698
MEDIUM 5.3 1 app

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web conten…

CVE-2019-11694
HIGH 7.5 1 app

A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an …

CVE-2019-11693
CRITICAL 9.8 1 app

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a …

CVE-2019-11692
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable …

CVE-2019-11691
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been fr…

CVE-2019-1130
HIGH 7.8 KEV

An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links, aka 'Windows Elevation of Privileg…

CVE-2018-20852
MEDIUM 5.3 1 app

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into se…

CVE-2019-1129
HIGH 7.8 KEV

Windows Elevation of Privilege Vulnerability

CVE-2019-1128
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1127
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1126
HIGH 5.3

ADFS Security Feature Bypass Vulnerability

CVE-2019-1124
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1123
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1122
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1121
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1120
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1119
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1118
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1117
HIGH 7.8

DirectWrite Remote Code Execution Vulnerability

CVE-2019-1108
HIGH 6.5

Remote Desktop Protocol Client Information Disclosure Vulnerability

CVE-2019-1102
CRITICAL 8.4

GDI+ Remote Code Execution Vulnerability

CVE-2019-1097
HIGH 5.5

DirectWrite Information Disclosure Vulnerability

CVE-2019-1096
HIGH 5.5

Win32k Information Disclosure Vulnerability

CVE-2019-1095
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2019-1094
HIGH 5.5

Windows GDI Information Disclosure Vulnerability

CVE-2019-1093
HIGH 5.5

DirectWrite Information Disclosure Vulnerability

CVE-2019-1091
HIGH 5.5

Microsoft unistore.dll Information Disclosure Vulnerability

CVE-2019-1090
HIGH 7.8

Windows dnsrslvr.dll Elevation of Privilege Vulnerability

CVE-2019-1089
HIGH 7.8

Windows RPCSS Elevation of Privilege Vulnerability

CVE-2019-1088
HIGH 7.8

Windows Audio Service Elevation of Privilege Vulnerability

CVE-2019-1087
HIGH 7.8

Windows Audio Service Elevation of Privilege Vulnerability