Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 089 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 089
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-02

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 089 entrées
CVE
CVE-2023-5174
CRITICAL 9.8

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free a…

CVE-2023-5171
MEDIUM 6.5

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potent…

CVE-2023-5169
MEDIUM 6.5

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable…

CVE-2023-5168
CRITICAL 9.8

A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable …

CVE-2023-40435
MEDIUM 5.5

This issue was addressed by enabling hardened runtime. This issue is fixed in Xcode 15. An app may be able to access App Store credentials.

CVE-2022-20917
MEDIUM 4.3

A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attack…

CVE-2023-26369
HIGH 7.8 KEV

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerabil…

CVE-2023-4909
MEDIUM 4.3

Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML pag…

CVE-2023-4908
MEDIUM 4.3

Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML pa…

CVE-2023-4907
MEDIUM 4.3

Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTM…

CVE-2023-4906
MEDIUM 4.3

Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTM…

CVE-2023-4905
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromi…

CVE-2023-4904
MEDIUM 4.3

Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a c…

CVE-2023-4903
MEDIUM 4.3

Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a craf…

CVE-2023-4902
MEDIUM 4.3

Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium…

CVE-2023-4901
MEDIUM 4.3

Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML p…

CVE-2023-4900
MEDIUM 4.3

Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a…

CVE-2023-39215
HIGH 7.1

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVE-2023-36766
HIGH 7.8

Microsoft Excel Information Disclosure Vulnerability

CVE-2023-36763
HIGH 7.5

Microsoft Outlook Information Disclosure Vulnerability

CVE-2023-36762
HIGH 7.3

Microsoft Word Remote Code Execution Vulnerability

CVE-2023-36761
MEDIUM 6.5 KEV

Microsoft Word Information Disclosure Vulnerability

CVE-2023-4863
HIGH 8.8 KEV

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write v…

CVE-2023-38162
HIGH · éditeur

DHCP Server Service Denial of Service Vulnerability

CVE-2023-38161
HIGH · éditeur

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-38160
HIGH · éditeur

Windows TCP/IP Information Disclosure Vulnerability

CVE-2023-38152
HIGH · éditeur

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-38150
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38149
HIGH · éditeur

Windows TCP/IP Denial of Service Vulnerability

CVE-2023-38148
CRITICAL · éditeur

Internet Connection Sharing (ICS) Remote Code Execution Vulnerability

CVE-2023-38147
HIGH · éditeur

Windows Miracast Wireless Display Remote Code Execution Vulnerability

CVE-2023-38146
HIGH · éditeur

Windows Themes Remote Code Execution Vulnerability

CVE-2023-38144
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38143
HIGH · éditeur

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2023-38142
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38141
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-38140
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2023-38139
HIGH · éditeur

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-36805
HIGH · éditeur

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVE-2023-36804
HIGH · éditeur

Windows GDI Elevation of Privilege Vulnerability

CVE-2023-36803
HIGH · éditeur

Windows Kernel Information Disclosure Vulnerability

CVE-2023-36802
HIGH · éditeur KEV

Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability

CVE-2023-36801
HIGH · éditeur

DHCP Server Service Information Disclosure Vulnerability

CVE-2023-35355
HIGH · éditeur

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

CVE-2023-4585
HIGH 8.8

Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha…

CVE-2023-4584
HIGH 8.8

Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence…

CVE-2023-4583
HIGH · éditeur

When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been dis…

CVE-2023-4582
HIGH 8.8

Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory…

CVE-2023-4581
MEDIUM 4.3

Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their pot…

CVE-2023-4580
MEDIUM · éditeur

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability …

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa