Vulnérabilités
Vulnérabilités des apps suivies
26 363 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.
- CVE correspondantes
- 26 363
- Activement exploitées
- 373
- Fenêtre de publication
- 1997-01-01 → 2026-10-06
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2023-29372
HIGH · éditeur
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability |
|
CVE-2023-29371
HIGH · éditeur
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29370
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-29369
HIGH · éditeur
Remote Procedure Call Runtime Denial of Service Vulnerability |
|
CVE-2023-29368
HIGH · éditeur
Windows Filtering Platform Elevation of Privilege Vulnerability |
|
CVE-2023-29367
HIGH · éditeur
iSCSI Target WMI Provider Remote Code Execution Vulnerability |
|
CVE-2023-29366
HIGH · éditeur
Windows Geolocation Service Remote Code Execution Vulnerability |
|
CVE-2023-29365
HIGH · éditeur
Windows Media Remote Code Execution Vulnerability |
|
CVE-2023-29364
HIGH · éditeur
Windows Authentication Elevation of Privilege Vulnerability |
|
CVE-2023-29363
CRITICAL · éditeur
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability |
|
CVE-2023-29362
HIGH · éditeur
Remote Desktop Client Remote Code Execution Vulnerability |
|
CVE-2023-29361
HIGH · éditeur
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability |
|
CVE-2023-29360
Microsoft Streaming Service Elevation of Privilege Vulnerability |
|
CVE-2023-29359
HIGH · éditeur
GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29358
HIGH · éditeur
Windows GDI Elevation of Privilege Vulnerability |
|
CVE-2023-29355
HIGH · éditeur
DHCP Server Service Information Disclosure Vulnerability |
|
CVE-2023-29352
HIGH · éditeur
Windows Remote Desktop Security Feature Bypass Vulnerability |
|
CVE-2023-29351
HIGH · éditeur
Windows Group Policy Elevation of Privilege Vulnerability |
|
CVE-2023-29346
HIGH · éditeur
NTFS Elevation of Privilege Vulnerability |
|
CVE-2023-24938
HIGH · éditeur
Windows CryptoAPI Denial of Service Vulnerability |
|
CVE-2023-24937
HIGH · éditeur
Windows CryptoAPI Denial of Service Vulnerability |
|
CVE-2023-33595
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c. |
|
CVE-2023-3079
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromi… |
|
CVE-2023-32215
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team repor… |
|
CVE-2023-32213
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird… |
|
CVE-2023-32212
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderb… |
|
CVE-2023-32211
A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. |
|
CVE-2023-32207
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefo… |
|
CVE-2023-32206
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102… |
|
CVE-2023-32205
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attac… |
|
CVE-2023-28176
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort… |
|
CVE-2023-28164
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability af… |
|
CVE-2023-28163
When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those … |
|
CVE-2023-28162
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash.… |
|
CVE-2023-25752
When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code… |
|
CVE-2023-25751
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially … |
|
CVE-2023-25746
HIGH 8.8
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c… |
|
CVE-2023-25742
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, T… |
|
CVE-2023-25739
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. Th… |
|
CVE-2023-25738
Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn wo… |
|
CVE-2023-25737
An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Th… |
|
CVE-2023-25735
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-… |
|
CVE-2023-25734
After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network … |
|
CVE-2023-25732
When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading … |
|
CVE-2023-25731
HIGH 8.8
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in … |
|
CVE-2023-25730
A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, result… |
|
CVE-2023-25729
Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user… |
|
CVE-2023-25728
The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe t… |
|
CVE-2023-23605
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of… |
|
CVE-2023-23604
MEDIUM 6.5
A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to byp… |
Gérez votre parc avec Appaloosa
Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.