Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 946 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 946
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-09-29

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 946 entrées
CVE
CVE-2022-33275
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2023-7024
HIGH 8.8 KEV

Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag…

CVE-2023-3742
MEDIUM 6.8

Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via ph…

CVE-2023-6864
HIGH · éditeur

Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-6863
HIGH · éditeur

The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnera…

CVE-2023-6862
HIGH 8.8

A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 1…

CVE-2023-6861
HIGH 8.8

The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6…

CVE-2023-6860
MEDIUM · éditeur

The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe…

CVE-2023-6859
HIGH 8.8

A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Fi…

CVE-2023-6858
HIGH · éditeur

Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunder…

CVE-2023-6857
MEDIUM 5.3

When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni…

CVE-2023-6856
HIGH · éditeur

The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an att…

CVE-2023-50762
MEDIUM 4.3

When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w…

CVE-2023-50761
MEDIUM 4.3

The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t…

CVE-2023-51384
MEDIUM 5.5

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of …

CVE-2023-6707
HIGH 8.8

Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom…

CVE-2023-6706
HIGH 8.8

Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potenti…

CVE-2023-6705
HIGH 8.8

Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…

CVE-2023-6704
HIGH 8.8

Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (…

CVE-2023-6703
HIGH 8.8

Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr…

CVE-2023-6702
HIGH 8.8

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi…

CVE-2023-49646
MEDIUM 6.4

Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-43585
HIGH 7.1

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of infor…

CVE-2023-43583
MEDIUM 4.9

Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user …

CVE-2023-36696
HIGH · éditeur

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-36391
HIGH · éditeur

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2023-36012
HIGH · éditeur

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-36011
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-36006
HIGH · éditeur

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

CVE-2023-36005
HIGH · éditeur

Windows Telephony Server Elevation of Privilege Vulnerability

CVE-2023-36004
HIGH · éditeur

Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability

CVE-2023-36003
HIGH · éditeur

XAML Diagnostics Elevation of Privilege Vulnerability

CVE-2023-35644
HIGH · éditeur

Windows Sysmain Service Elevation of Privilege Vulnerability

CVE-2023-35643
HIGH · éditeur

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-35642
HIGH · éditeur

Internet Connection Sharing (ICS) Denial of Service Vulnerability

CVE-2023-35641
CRITICAL · éditeur

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-35639
HIGH · éditeur

Microsoft ODBC Driver Remote Code Execution Vulnerability

CVE-2023-35638
HIGH · éditeur

DHCP Server Service Denial of Service Vulnerability

CVE-2023-35635
HIGH · éditeur

Windows Kernel Denial of Service Vulnerability

CVE-2023-35634
HIGH · éditeur

Windows Bluetooth Driver Remote Code Execution Vulnerability

CVE-2023-35632
HIGH · éditeur

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

CVE-2023-35631
HIGH · éditeur

Win32k Elevation of Privilege Vulnerability

CVE-2023-35630
CRITICAL · éditeur

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-35628
CRITICAL · éditeur

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2023-35622
HIGH · éditeur

Windows DNS Spoofing Vulnerability

CVE-2023-21740
HIGH · éditeur

Windows Media Remote Code Execution Vulnerability

CVE-2023-20588
HIGH · éditeur

AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice

CVE-2023-6507
MEDIUM 6.1

An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. …

CVE-2023-6512
MEDIUM 6.5

Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe…

CVE-2023-6511
MEDIUM 4.3

Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML p…

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa