Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerabilities

Tracked app vulnerabilities

8,473 CVEs affect a tracked app or OS (all severities, Windows). 213 of them are in the CISA KEV catalog, meaning exploitation is confirmed.

Matching CVEs
8,473
Actively exploited
213
Publication window
2002-10-04 → 2026-08-19

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

8,473 entries Windows Clear all
CVE
CVE-2017-5403
CRITICAL 9.8 1 app

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, res…

CVE-2017-5402
CRITICAL 9.8 1 app

A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This result…

CVE-2017-5401
CRITICAL 9.8 1 app

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vu…

CVE-2017-5400
CRITICAL 9.8 1 app

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vuln…

CVE-2017-5399
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of the…

CVE-2017-5398
CRITICAL 9.8 1 app

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some …

CVE-2017-5396
CRITICAL 9.8 1 app

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. Th…

CVE-2017-5390
CRITICAL 9.8 1 app

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for …

CVE-2017-5383
MEDIUM 5.3 1 app

URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks i…

CVE-2017-5380
CRITICAL 9.8 1 app

A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and…

CVE-2017-5378
HIGH 7.5 1 app

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, an…

CVE-2017-5376
CRITICAL 9.8 1 app

Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVE-2017-5375
CRITICAL 9.8 1 app

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <…

CVE-2017-5373
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough …

CVE-2016-9905
HIGH 8.8 1 app

A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbir…

CVE-2016-9904
HIGH 7.5 1 app

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be u…

CVE-2016-9900
HIGH 7.5 1 app

External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cros…

CVE-2016-9899
CRITICAL 9.8 1 app

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5…

CVE-2016-9898
CRITICAL 9.8 1 app

Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR …

CVE-2016-9897
HIGH 7.5 1 app

Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vuln…

CVE-2016-9895
MEDIUM 6.1 1 app

Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects…

CVE-2016-9893
CRITICAL 9.8 1 app

Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some …

CVE-2016-9079
HIGH 7.5 KEV 1 app

A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox a…

CVE-2016-9074
MEDIUM 5.9 1 app

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1.…

CVE-2016-9066
HIGH 7.5 1 app

A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability…

CVE-2016-9063
CRITICAL 9.8 1 app

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

CVE-2016-5297
CRITICAL 9.8 1 app

An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderb…

CVE-2016-5296
HIGH 7.5 1 app

A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability a…

CVE-2016-5294
MEDIUM 5.5 1 app

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires…

CVE-2016-5291
MEDIUM 5.5 1 app

A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 4…

CVE-2016-5290
CRITICAL 9.8 1 app

Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough ef…

CVE-2018-11235
HIGH 7.8 1 app

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a craft…

CVE-2018-11233
HIGH 7.5 1 app

In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can re…

CVE-2017-17689
MEDIUM 5.9 3 apps

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

CVE-2017-17688
MEDIUM 5.9 1 app

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: t…

CVE-2018-8174
HIGH 7.5 KEV

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution …

CVE-2018-8897
HIGH 7.0

Windows Kernel Elevation of Privilege Vulnerability

CVE-2018-8170
HIGH 7.0

Windows Image Elevation of Privilege Vulnerability

CVE-2018-8167
HIGH 7.0

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2018-8166
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2018-8165
HIGH 7.0

DirectX Graphics Kernel Elevation of Privilege Vulnerability

CVE-2018-8164
HIGH 7.0

Win32k Elevation of Privilege Vulnerability

CVE-2018-8142
HIGH 5.3

Windows Security Feature Bypass Vulnerability

CVE-2018-8141
HIGH 4.7

Windows Kernel Information Disclosure Vulnerability

CVE-2018-8136
LOW 6.5

Windows Remote Code Execution Vulnerability

CVE-2018-8134
HIGH 7.0

Windows Elevation of Privilege Vulnerability

CVE-2018-8132
HIGH 5.3

Windows Security Feature Bypass Vulnerability

CVE-2018-8129
HIGH 5.3

Windows Security Feature Bypass Vulnerability

CVE-2018-8127
HIGH 4.7

Windows Kernel Information Disclosure Vulnerability

CVE-2018-8124
HIGH 7.0

Win32k Elevation of Privilege Vulnerability