Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

844 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2017-0143
CRITICAL 8.1 KEV

Windows SMB Remote Code Execution Vulnerability

CVE-2017-0109
CRITICAL 7.6

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2017-0104
CRITICAL 8.1

iSNS Server Memory Corruption Vulnerability

CVE-2017-0084
CRITICAL 8.8

Windows Uniscribe Remote Code Execution Vulnerability

CVE-2017-0075
CRITICAL 7.6

Windows Hyper-V Remote Code Execution Vulnerability

CVE-2017-0021
CRITICAL 4.3

Hyper-V vSMB Remote Code Execution Vulnerability

CVE-2017-0014
CRITICAL 7.5

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2016-7274
CRITICAL 7.5

Windows Uniscribe Remote Code Execution Vulnerability

CVE-2016-7273
CRITICAL 4.2

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2016-7272
CRITICAL 7.5

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2016-9535
CRITICAL 9.8 Network

tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when d…

CVE-2016-7256
CRITICAL 8.8 KEV

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2016-7248
CRITICAL

Microsoft Video Control Remote Code Execution Vulnerability

CVE-2016-7212
CRITICAL 8.8

Windows Remote Code Execution Vulnerability

CVE-2016-7205
CRITICAL 7.1

Windows Animation Manager Memory Corruption Vulnerability

CVE-2016-3396
CRITICAL

GDI+ Remote Code Execution Vulnerability

CVE-2016-3393
CRITICAL 8.8 KEV

GDI+ Remote Code Execution Vulnerability

CVE-2016-0142
CRITICAL

Microsoft Video Control Remote Code Execution Vulnerability

CVE-2016-3375
CRITICAL 7.5

Scripting Engine Memory Corruption Vulnerability

CVE-2016-3356
CRITICAL 6.7

GDI+ Remote Code Execution Vulnerability

CVE-2016-5636
CRITICAL 9.8 Network 1 apps

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attacker…

CVE-2016-3301
CRITICAL 8.8

Microsoft Graphics Remote Code Execution Vulnerability

CVE-2016-3238
CRITICAL 8.8

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2016-3236
CRITICAL 9.8 Network

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Win…

CVE-2016-2324
CRITICAL 9.8 Network 1 apps

Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-…

CVE-2016-2315
CRITICAL 9.8 Network 1 apps

revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many…

CVE-2014-1532
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24…

CVE-2014-1524
CRITICAL 9.8 Network 1 apps

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before …

CVE-2014-1514
CRITICAL 9.8 Network 1 apps

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the l…

CVE-2014-1511
CRITICAL 9.8 Network 1 apps

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocke…

CVE-2014-1510
CRITICAL 9.8 Network 1 apps

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attac…

CVE-2014-1508
CRITICAL 9.1 Network 1 apps

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 all…

CVE-2014-1493
CRITICAL 9.8 Network 1 apps

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey…

CVE-2014-1486
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonk…

CVE-2014-1477
CRITICAL 9.8 Network 1 apps

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey…

CVE-2013-6671
CRITICAL 9.8 Network 1 apps

The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allo…

CVE-2013-5618
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.…

CVE-2013-5616
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbi…

CVE-2013-5615
CRITICAL 9.8 Network 1 apps

The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properl…

CVE-2013-5613
CRITICAL 9.8 Network 1 apps

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before…

CVE-2013-5609
CRITICAL 9.8 Network 1 apps

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey…

CVE-2010-3765
CRITICAL 9.8 KEV Network 1 apps

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when Ja…

CVE-2010-1205
CRITICAL 9.8 Network 1 apps

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbi…

CVE-2007-4559
CRITICAL 9.8 Network 1 apps

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to over…