Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 901 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 901
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 901 entrées
CVE
CVE-2025-43364
HIGH 7.8

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26.1. An app may be able t…

CVE-2025-43361
HIGH 7.8

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO…

CVE-2025-43360
MEDIUM 5.5

The issue was addressed with improved UI. This issue is fixed in iOS 26 and iPadOS 26. Password fields may be unintentionally revealed.

CVE-2025-43350
LOW 2.4

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An attacker may be able to view restricted con…

CVE-2025-43348
MEDIUM 5.5

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may bypass Gat…

CVE-2025-43345
MEDIUM 5.5

A correctness issue was addressed with improved checks. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma…

CVE-2025-43338
HIGH 7.1

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26 and iPadOS 26, macOS Sonoma 14.8.2, macOS Sonoma 14.8.…

CVE-2025-43336
MEDIUM 4.4

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app with…

CVE-2025-43335
MEDIUM 5.5

The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to a…

CVE-2025-43334
MEDIUM 5.5

This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be …

CVE-2025-43323
HIGH 8.1

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26 and iPadOS 26, macOS Tahoe 26, tvOS 26, visionOS 26, watchOS 26. An …

CVE-2025-43322
MEDIUM 5.5

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may be able to acc…

CVE-2025-43309
LOW 2.4

A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical access to an iOS device may be able to…

CVE-2025-43288
MEDIUM 5.5

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26. An app may be able to bypass Privacy …

CVE-2025-6442
HIGH · éditeur

[Apple Ruby] Multiple issues in ruby

CVE-2025-53906
MEDIUM · éditeur

[Apple Vim] A path handling issue was addressed with improved validation

CVE-2024-49761
HIGH · éditeur

[Apple Ruby] Multiple issues in ruby

CVE-2024-43398
MEDIUM · éditeur

[Apple Ruby] Multiple issues in ruby

CVE-2025-6075
MEDIUM 5.5

If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.

CVE-2025-12380
CRITICAL 9.8

Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC c…

CVE-2025-43313
MEDIUM 5.5

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be abl…

CVE-2025-43282
MEDIUM 5.5

A double free issue was addressed with improved memory management. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, macOS So…

CVE-2025-43281
HIGH 7.8

The issue was addressed with improved authentication. This issue is fixed in macOS Sequoia 15.6. A local attacker may be able to elevate their privileges.

CVE-2025-43280
MEDIUM 4.7

The issue was resolved by not loading remote images. This issue is fixed in iOS 18.6 and iPadOS 18.6. Forwarding an email could display remote images in Mail i…

CVE-2025-59238
HIGH 7.8

Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.

CVE-2025-59235
HIGH 7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-59234
CRITICAL · éditeur

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-59233
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59232
HIGH 7.1

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

CVE-2025-59231
HIGH 7.8

Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59227
CRITICAL · éditeur

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

CVE-2025-59225
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59224
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59223
HIGH 7.8

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

CVE-2025-59222
HIGH 7.8

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-59221
HIGH 7.0

Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.

CVE-2025-11721
CRITICAL 9.8

Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could h…

CVE-2025-11720
HIGH 8.1

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted…

CVE-2025-11719
CRITICAL 9.8

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.…

CVE-2025-11718
MEDIUM 6.5

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychang…

CVE-2025-11717
CRITICAL 9.1

When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a password-related screen was the last one bein…

CVE-2025-11716
MEDIUM 6.5

Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnerability was fixed in Firefox 144 and Thu…

CVE-2025-11715
HIGH 8.8

Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruptio…

CVE-2025-11714
HIGH 8.8

Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence…

CVE-2025-11713
HIGH 8.1

Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the app…

CVE-2025-11712
MEDIUM 6.1

A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a…

CVE-2025-11711
MEDIUM 6.5

There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability was fixed in Firefox 144, Firefo…

CVE-2025-11710
CRITICAL 9.8

A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised proce…

CVE-2025-11709
CRITICAL 9.8

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability …

CVE-2025-11708
CRITICAL 9.8

Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa