Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 363 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 363
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 363 entrées
CVE
CVE-2022-31740
HIGH 8.8

On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vu…

CVE-2022-31739
HIGH 8.8

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths th…

CVE-2022-31738
MEDIUM 6.5

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofin…

CVE-2022-31737
CRITICAL 9.8

A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability aff…

CVE-2022-31736
CRITICAL 9.8

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firef…

CVE-2022-2505
HIGH 8.8

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and…

CVE-2022-2226
MEDIUM 6.5

An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, th…

CVE-2022-2200
HIGH 8.8

If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code e…

CVE-2022-29917
CRITICAL 9.8

Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR…

CVE-2022-29916
MEDIUM 6.5

Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the bro…

CVE-2022-29914
MEDIUM 6.5

When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This v…

CVE-2022-29913
MEDIUM 6.5

The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerabili…

CVE-2022-29912
MEDIUM 6.1

Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91…

CVE-2022-29911
MEDIUM 6.1

An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>…

CVE-2022-29909
HIGH 8.8

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wr…

CVE-2022-28289
HIGH 8.8

Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in T…

CVE-2022-28286
MEDIUM 5.4

Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnera…

CVE-2022-28285
MEDIUM 6.5

When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vulnerability this c…

CVE-2022-28282
MEDIUM 6.5

By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript execution and then re…

CVE-2022-28281
HIGH 8.8

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would hav…

CVE-2022-26387
HIGH 7.5

When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file c…

CVE-2022-26386
MEDIUM 6.5

Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to downl…

CVE-2022-26384
CRITICAL 9.6

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a l…

CVE-2022-26383
MEDIUM 4.3

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Fir…

CVE-2022-26381
HIGH 8.8

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects…

CVE-2022-22764
HIGH 8.8

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed e…

CVE-2022-22763
HIGH 8.8

When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability a…

CVE-2022-22761
HIGH 8.8

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Ex…

CVE-2022-22760
MEDIUM 6.5

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-scrip…

CVE-2022-22759
CRITICAL 9.6

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a Java…

CVE-2022-22756
HIGH 8.8

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script whic…

CVE-2022-22754
MEDIUM 6.5

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new …

CVE-2022-22753
HIGH 7.1

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This c…

CVE-2022-22751
HIGH 8.8

Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memor…

CVE-2022-22748
MEDIUM 6.5

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulner…

CVE-2022-22747
MEDIUM 6.5

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed t…

CVE-2022-22746
MEDIUM 5.9

A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only…

CVE-2022-22745
MEDIUM 6.5

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefo…

CVE-2022-22744
HIGH 8.8

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if …

CVE-2022-22743
MEDIUM 4.3

When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mod…

CVE-2022-22742
MEDIUM 6.5

When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerabil…

CVE-2022-22741
HIGH 7.5

When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR <…

CVE-2022-22740
HIGH 8.8

Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially ex…

CVE-2022-22739
MEDIUM 6.5

Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.…

CVE-2022-22738
HIGH 8.8

Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. …

CVE-2022-22737
HIGH 7.5

Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a p…

CVE-2022-1834
MEDIUM 6.5

When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would have displaye…

CVE-2022-1520
MEDIUM 4.3

When viewing an email message A, which contains an attached message B, where B is encrypted or digitally signed or both, Thunderbird may show an incorrect encr…

CVE-2022-1197
MEDIUM 5.4

When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was not yet r…

CVE-2022-1196
MEDIUM 6.5

After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnera…

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa