Vulnérabilités
Vulnérabilités des apps suivies
25 929 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 929
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2025-5269
Memory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of memory corruption and we presume that with enough effort t… |
|
CVE-2025-5268
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption… |
|
CVE-2025-5267
MEDIUM 5.4
A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability was fixed in … |
|
CVE-2025-5266
MEDIUM 4.3
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed… |
|
CVE-2025-5265
MEDIUM 4.8
Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially lead… |
|
CVE-2025-5264
MEDIUM 4.8
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leadin… |
|
CVE-2025-5263
MEDIUM 4.3
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability was fixed… |
|
CVE-2025-5262
HIGH 7.5
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memo… |
|
CVE-2025-5020
MEDIUM 4.3
Opening maliciously-crafted URLs in Firefox from other apps such as Safari could have allowed attackers to spoof website addresses if the URLs utilized non-HTT… |
|
CVE-2025-31262
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, w… |
|
CVE-2025-31185
LOW 3.3
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3. Photos in the Hidden Photos Album may be viewed without auth… |
|
CVE-2025-24189
The issue was addressed with improved checks. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, tvOS 18.3, visionOS 2.3, watchO… |
|
CVE-2025-24184
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, tvOS 18.3, visionOS … |
|
CVE-2025-24183
MEDIUM 5.5
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A local user may be able to… |
|
CVE-2025-4919
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 1… |
|
CVE-2025-4918
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 1… |
|
CVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.… |
|
CVE-2025-3932
MEDIUM 6.5
It was possible to craft an email that showed a tracking link as an attachment. If the user attempted to open the attachment, Thunderbird automatically accesse… |
|
CVE-2025-3909
HIGH 8.1
Thunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute JavaScript in the file:/// context. By crafting a nested ema… |
|
CVE-2025-3875
HIGH 7.5
Thunderbird parses addresses in a way that can allow sender spoofing in case the server allows an invalid From address to be used. For example, if the From hea… |
|
CVE-2025-32704
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30388
HIGH · éditeur
Heap-based buffer overflow in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30386
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30383
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30381
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30379
Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30377
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30376
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-30375
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-29979
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-29977
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
|
CVE-2025-32709
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2025-32707
HIGH · éditeur
NTFS Elevation of Privilege Vulnerability |
|
CVE-2025-32706
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-32701
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-30400
Microsoft DWM Core Library Elevation of Privilege Vulnerability |
|
CVE-2025-30397
Scripting Engine Memory Corruption Vulnerability |
|
CVE-2025-30394
HIGH · éditeur
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability |
|
CVE-2025-30385
HIGH · éditeur
Windows Common Log File System Driver Elevation of Privilege Vulnerability |
|
CVE-2025-29974
HIGH · éditeur
Windows Kernel Information Disclosure Vulnerability |
|
CVE-2025-29971
HIGH · éditeur
Web Threat Defense (WTD.sys) Denial of Service Vulnerability |
|
CVE-2025-29970
HIGH · éditeur
Microsoft Brokering File System Elevation of Privilege Vulnerability |
|
CVE-2025-29969
HIGH · éditeur
MS-EVEN RPC Remote Code Execution Vulnerability |
|
CVE-2025-29968
HIGH · éditeur
Active Directory Certificate Services (AD CS) Denial of Service Vulnerability |
|
CVE-2025-29967
CRITICAL · éditeur
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-29966
CRITICAL · éditeur
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2025-29964
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29963
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29962
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2025-29961
HIGH · éditeur
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.