Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,473
Actively exploited
213
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,473 entries Windows Clear all
CVE
CVE-2018-5102
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerabi…

CVE-2018-5099
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in…

CVE-2018-5098
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially explo…

CVE-2018-5097
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the…

CVE-2018-5096
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affe…

CVE-2018-5095
CRITICAL 9.8 1 app

An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the u…

CVE-2018-5089
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7848
MEDIUM 5.3 1 app

RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.

CVE-2017-7847
MEDIUM 4.3 1 app

Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.

CVE-2017-7846
HIGH 8.8 1 app

It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard…

CVE-2017-7845
HIGH 8.8 1 app

A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an inco…

CVE-2017-7830
MEDIUM 6.5 1 app

The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs…

CVE-2017-7829
MEDIUM 5.3 1 app

It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed i…

CVE-2017-7828
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a…

CVE-2017-7826
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7825
MEDIUM 5.3 1 app

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name …

CVE-2017-7824
CRITICAL 9.8 1 app

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being …

CVE-2017-7823
MEDIUM 5.4 1 app

The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keywo…

CVE-2017-7819
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. T…

CVE-2017-7818
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. T…

CVE-2017-7814
HIGH 7.8 1 app

File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its bl…

CVE-2017-7810
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2017-7809
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results i…

CVE-2017-7807
HIGH 8.1 1 app

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requir…

CVE-2017-7805
HIGH 7.5 1 app

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the han…

CVE-2017-7804
HIGH 7.5 1 app

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary d…

CVE-2017-7803
HIGH 7.5 1 app

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of C…

CVE-2017-7802
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack…

CVE-2017-7801
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while…

CVE-2017-7800
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This res…

CVE-2017-7793
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially expl…

CVE-2017-7792
CRITICAL 9.8 1 app

A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This resul…

CVE-2017-7791
MEDIUM 5.3 1 app

On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoo…

CVE-2017-7787
HIGH 7.5 1 app

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page…

CVE-2017-7786
CRITICAL 9.8 1 app

A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulne…

CVE-2017-7785
CRITICAL 9.8 1 app

A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable…

CVE-2017-7784
CRITICAL 9.8 1 app

A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potent…

CVE-2017-7782
MEDIUM 5.3 1 app

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This a…

CVE-2017-7779
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume …

CVE-2017-7778
CRITICAL 9.8 1 app

A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized me…

CVE-2017-7765
HIGH 7.5 1 app

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, t…

CVE-2017-7764
MEDIUM 5.3 1 app

Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as th…

CVE-2017-7763
MEDIUM 5.3 1 app

Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing at…

CVE-2017-7758
CRITICAL 9.1 1 app

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerabilit…

CVE-2017-7757
CRITICAL 9.8 1 app

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a pote…

CVE-2017-7756
CRITICAL 9.8 1 app

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable…

CVE-2017-7755
HIGH 7.8 1 app

The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This allows privileged e…

CVE-2017-7754
HIGH 7.5 1 app

An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52…

CVE-2017-7753
CRITICAL 9.1 1 app

An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbir…

CVE-2017-7752
HIGH 8.8 1 app

A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This resul…