Skip to content
Appaloosa Scout

Vulnerabilities

Tracked app vulnerabilities

773 entries

Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.

CVE
CVE-2025-12084
MEDIUM 5.3 Network 1 apps

When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_cache() the algorithm is quadratic. Avail…

CVE-2025-13836
MEDIUM 7.5 Network 1 apps

When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content-Length. This allows a malicious server…

CVE-2025-52331
MEDIUM 6.1 Network 1 apps

Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the …

CVE-2025-6075
MEDIUM 5.5 Local 1 apps

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-11716
MEDIUM 6.5 Network 1 apps

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11712
MEDIUM 6.1 Network 1 apps

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5 Network 1 apps

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-59502
MEDIUM 7.5

Remote Procedure Call Denial of Service Vulnerability

CVE-2025-10536
MEDIUM 6.2 Local 1 apps

Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140…

CVE-2025-10532
MEDIUM 6.5 Network 1 apps

Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird…

CVE-2025-10531
MEDIUM 5.4 Network 1 apps

Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.

CVE-2025-10529
MEDIUM 6.5 Network 1 apps

Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.

CVE-2025-9181
MEDIUM 6.5 Network 1 apps

Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, T…

CVE-2025-53779
MEDIUM 7.2

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2025-8033
MEDIUM 6.5 Network 1 apps

The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in…

CVE-2025-8027
MEDIUM 6.5 Network 1 apps

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulner…

CVE-2025-49464
MEDIUM 6.5 Network 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorised user to conduct a denial of service via network access.

CVE-2025-46789
MEDIUM 6.5 Network 1 apps

Classic buffer overflow in certain Zoom Clients for Windows may allow an authorized user to conduct a denial of service via network access.

CVE-2025-49760
MEDIUM 3.5

Windows Storage Spoofing Vulnerability

CVE-2025-5986
MEDIUM 6.5 Network 1 apps

A crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf files to the user's desktop or home directory without prompti…

CVE-2025-2884
MEDIUM 6.6 Local

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with…

CVE-2025-3932
MEDIUM 6.5 Network 1 apps

It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse…

CVE-2025-4092
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort s…

CVE-2025-4089
MEDIUM 5.1 Local 1 apps

Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading t…

CVE-2025-4088
MEDIUM 6.5 Network 1 apps

A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitrary endpoints on any site that had invo…

CVE-2025-4087
MEDIUM 4.8 Network 1 apps

A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This cou…

CVE-2025-4084
MEDIUM 5.7 Network 1 apps

Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leadi…

CVE-2025-4082
MEDIUM 5.9 Network 1 apps

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate…

CVE-2025-3523
MEDIUM 6.4 Network 1 apps

When an email contains multiple attachments with external links via the X-Mozilla-External-Attachment-URL header, only the last link is shown when hovering ove…

CVE-2025-3522
MEDIUM 6.3 Network 1 apps

Thunderbird processes the X-Mozilla-External-Attachment-URL header to handle attachments which can be hosted externally. When an email is opened, Thunderbird a…

CVE-2025-2830
MEDIUM 6.3 Network 1 apps

By crafting a malformed file name for an attachment in a multipart message, an attacker can trick Thunderbird into including a directory listing of /tmp when t…

CVE-2025-31334
MEDIUM 6.8 Network 1 apps

Issue that bypasses the "Mark of the Web" security warning function for files when opening a symbolic link that points to an executable file exists in WinRAR v…

CVE-2025-3031
MEDIUM 6.5 Network 1 apps

An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability was fixed in Firefox 137 and Thunderbird 137.

CVE-2025-3028
MEDIUM 6.5 Network 1 apps

JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability was fixed in Firefox 137, Firef…

CVE-2025-26695
MEDIUM 5.3 Local 1 apps

When requesting an OpenPGP key from a WKD server, an incorrect padding size was used and a network observer could have learned the length of the requested emai…

CVE-2025-1938
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption a…

CVE-2025-1935
MEDIUM 4.3 Network 1 apps

A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability was fixed in Firefox 136, Firefox ESR…

CVE-2025-1934
MEDIUM 6.5 Network 1 apps

It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was no…

CVE-2025-1019
MEDIUM 4.3 Network 1 apps

The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. …

CVE-2025-1018
MEDIUM 5.3 Network 1 apps

The fullscreen notification is prematurely hidden when fullscreen is re-requested quickly by the user. This could have been leveraged to perform a potential sp…

CVE-2025-1015
MEDIUM 5.4 Network 1 apps

The Thunderbird Address Book URI fields contained unsanitized links. This could be used by an attacker to create and export an address book containing a malici…

CVE-2025-1013
MEDIUM 6.5 Network 1 apps

A race condition could have led to private browsing tabs being opened in normal browsing windows. This could have resulted in a potential privacy leak. This vu…

CVE-2025-0510
MEDIUM 6.5 Network 1 apps

Thunderbird displayed an incorrect sender address if the From field of an email used the invalid group name syntax that is described in CVE-2024-49040. This vu…

CVE-2025-0243
MEDIUM 5.1 Local 1 apps

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption a…

CVE-2025-0242
MEDIUM 6.5 Network 1 apps

Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bug…

CVE-2025-0240
MEDIUM 4.0 Local 1 apps

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability w…

CVE-2025-0239
MEDIUM 4.0 Local 1 apps

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Fi…

CVE-2025-0238
MEDIUM 5.3 Network 1 apps

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability …

CVE-2025-0237
MEDIUM 5.4 Network 1 apps

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal bein…

CVE-2024-11708
MEDIUM 6.5 Network 1 apps

Missing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affects Firefox < 133 an…