Vulnérabilités
Vulnérabilités des apps suivies
25 946 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 25 946
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-09-29
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2022-33275
HIGH · éditeur
Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir. |
|
CVE-2023-7024
Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML pag… |
|
CVE-2023-3742
Insufficient policy enforcement in ADB in Google Chrome on ChromeOS prior to 114.0.5735.90 allowed a local attacker to bypass device policy restrictions via ph… |
|
CVE-2023-6864
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume tha… |
|
CVE-2023-6863
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnera… |
|
CVE-2023-6862
HIGH 8.8
A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 1… |
|
CVE-2023-6861
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6… |
|
CVE-2023-6860
The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affe… |
|
CVE-2023-6859
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Fi… |
|
CVE-2023-6858
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunder… |
|
CVE-2023-6857
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Uni… |
|
CVE-2023-6856
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an att… |
|
CVE-2023-50762
MEDIUM 4.3
When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This is because the text w… |
|
CVE-2023-50761
MEDIUM 4.3
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare t… |
|
CVE-2023-51384
MEDIUM 5.5
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of … |
|
CVE-2023-6707
Use after free in CSS in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom… |
|
CVE-2023-6706
Use after free in FedCM in Google Chrome prior to 120.0.6099.109 allowed a remote attacker who convinced a user to engage in specific UI interaction to potenti… |
|
CVE-2023-6705
Use after free in WebRTC in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch… |
|
CVE-2023-6704
Use after free in libavif in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted image file. (… |
|
CVE-2023-6703
Use after free in Blink in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chr… |
|
CVE-2023-6702
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-49646
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access. |
|
CVE-2023-43585
HIGH 7.1
Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of infor… |
|
CVE-2023-43583
Cryptographic issues Zoom Mobile App for Android, Zoom Mobile App for iOS, and Zoom SDKs for Android and iOS before version 5.16.0 may allow a privileged user … |
|
CVE-2023-36696
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-36391
HIGH · éditeur
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability |
|
CVE-2023-36012
HIGH · éditeur
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-36011
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-36006
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-36005
HIGH · éditeur
Windows Telephony Server Elevation of Privilege Vulnerability |
|
CVE-2023-36004
HIGH · éditeur
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability |
|
CVE-2023-36003
HIGH · éditeur
XAML Diagnostics Elevation of Privilege Vulnerability |
|
CVE-2023-35644
HIGH · éditeur
Windows Sysmain Service Elevation of Privilege Vulnerability |
|
CVE-2023-35643
HIGH · éditeur
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-35642
HIGH · éditeur
Internet Connection Sharing (ICS) Denial of Service Vulnerability |
|
CVE-2023-35641
CRITICAL · éditeur
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35639
HIGH · éditeur
Microsoft ODBC Driver Remote Code Execution Vulnerability |
|
CVE-2023-35638
HIGH · éditeur
DHCP Server Service Denial of Service Vulnerability |
|
CVE-2023-35635
HIGH · éditeur
Windows Kernel Denial of Service Vulnerability |
|
CVE-2023-35634
HIGH · éditeur
Windows Bluetooth Driver Remote Code Execution Vulnerability |
|
CVE-2023-35632
HIGH · éditeur
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability |
|
CVE-2023-35631
HIGH · éditeur
Win32k Elevation of Privilege Vulnerability |
|
CVE-2023-35630
CRITICAL · éditeur
Internet Connection Sharing (ICS) Remote Code Execution Vulnerability |
|
CVE-2023-35628
CRITICAL · éditeur
Windows MSHTML Platform Remote Code Execution Vulnerability |
|
CVE-2023-35622
HIGH · éditeur
Windows DNS Spoofing Vulnerability |
|
CVE-2023-21740
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-20588
HIGH · éditeur
AMD: CVE-2023-20588 AMD Speculative Leaks Security Notice |
|
CVE-2023-6507
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. … |
|
CVE-2023-6512
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe… |
|
CVE-2023-6511
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML p… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.