Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 946 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 946
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 946 entrées
CVE
CVE-2024-2631
MEDIUM 4.3

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium…

CVE-2024-2630
MEDIUM 6.5

Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chrom…

CVE-2024-2629
MEDIUM 4.3

Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securi…

CVE-2024-2628
MEDIUM 4.3

Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium…

CVE-2024-2627
HIGH 8.8

Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2024-2626
MEDIUM 6.5

Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML p…

CVE-2024-2625
HIGH 8.8

Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page…

CVE-2024-2616
LOW 2.7

To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects F…

CVE-2024-2614
HIGH · éditeur

Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2024-2612
HIGH · éditeur

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code …

CVE-2024-2611
MEDIUM · éditeur

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox…

CVE-2024-2610
MEDIUM 6.1

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability a…

CVE-2024-2609
MEDIUM 6.1

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerabi…

CVE-2024-2608
HIGH 8.4

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underalloc…

CVE-2024-2607
HIGH · éditeur

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other opera…

CVE-2024-2606
LOW 3.7

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Fi…

CVE-2024-2605
MEDIUM · éditeur

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows …

CVE-2023-5388
MEDIUM 6.5

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data…

CVE-2024-23298
MEDIUM 5.5

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVE-2024-26246
LOW 3.9

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

CVE-2023-42938
HIGH 7.8

A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.13.1 for Windows. A local attacker may be able to elevate their privileges.

CVE-2024-2400
HIGH 8.8

Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted H…

CVE-2024-26204
HIGH 7.5

Outlook for Android Information Disclosure Vulnerability

CVE-2024-21390
HIGH 7.1

Microsoft Authenticator Elevation of Privilege Vulnerability

CVE-2024-26197
HIGH · éditeur

Windows Standards-Based Storage Management Service Denial of Service Vulnerability

CVE-2024-26190
HIGH · éditeur

Microsoft QUIC Denial of Service Vulnerability

CVE-2024-26185
HIGH · éditeur

Windows Compressed Folder Tampering Vulnerability

CVE-2024-26182
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-26181
HIGH · éditeur

Windows Kernel Denial of Service Vulnerability

CVE-2024-26178
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-26177
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2024-26176
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-26174
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2024-26173
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-26170
HIGH · éditeur

Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability

CVE-2024-26169
HIGH · éditeur KEV

Windows Error Reporting Service Elevation of Privilege Vulnerability

CVE-2024-26166
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-26162
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVE-2024-26161
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-26160
HIGH · éditeur

Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability

CVE-2024-26159
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVE-2024-21451
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVE-2024-21450
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-21446
HIGH · éditeur

NTFS Elevation of Privilege Vulnerability

CVE-2024-21445
HIGH · éditeur

Windows USB Print Driver Elevation of Privilege Vulnerability

CVE-2024-21444
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-21443
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-21442
HIGH · éditeur

Windows USB Print Driver Elevation of Privilege Vulnerability

CVE-2024-21441
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2024-21440
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa