Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

26 374 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 373 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
26 374
Activement exploitées
373
Fenêtre de publication
1997-01-01 → 2026-10-06

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

26 374 entrées
CVE
CVE-2021-0577
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0515
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0514
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0486
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2021-0441
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-11307
CRITICAL · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0417
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-0368
HIGH · éditeur

Indexée via Android Security Bulletin ; métadonnées NVD complètes à venir.

CVE-2020-17759
HIGH 8.8

An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the us…

CVE-2021-29967
HIGH 8.8

Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we pres…

CVE-2021-29964
HIGH 7.1

A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only …

CVE-2021-29957
MEDIUM 4.3

If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, Thunderbird did not indi…

CVE-2021-29956
MEDIUM 4.3

OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local disk. The master pass…

CVE-2021-29951
MEDIUM 6.5

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop th…

CVE-2021-29950
HIGH 7.5

Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure, the secret key may…

CVE-2021-29949
HIGH 7.8

When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filename that isn't distri…

CVE-2021-29948
LOW 2.5

Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local process or user is replac…

CVE-2021-29946
HIGH 8.8

Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc hea…

CVE-2021-29945
MEDIUM 6.5

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32…

CVE-2021-24002
HIGH 8.8

When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary c…

CVE-2021-23999
HIGH 8.8

If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should…

CVE-2021-23998
MEDIUM 6.5

Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox E…

CVE-2021-23995
HIGH 8.8

When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been expl…

CVE-2021-23994
HIGH 8.8

A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10,…

CVE-2021-23993
MEDIUM 6.5

An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpenPGP key with a sub…

CVE-2021-23992
MEDIUM 4.3

Thunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. An attacker may create a crafted version of an OpenPGP key,…

CVE-2021-23991
MEDIUM 6.8

If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updated key has not yet b…

CVE-2021-30553
HIGH 8.8

Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML p…

CVE-2021-30552
HIGH 8.8

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially e…

CVE-2021-30551
HIGH 8.8 KEV

Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30550
HIGH 8.8

Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentiall…

CVE-2021-30549
HIGH 8.8

Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially …

CVE-2021-30548
HIGH 8.8

Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30547
HIGH 8.8

Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted…

CVE-2021-30546
HIGH 8.8

Use after free in Autofill in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-30545
HIGH 8.8

Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit …

CVE-2021-30544
HIGH 8.8

Use after free in BFCache in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2021-24035
CRITICAL 9.1

A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed …

CVE-2021-31949
HIGH 7.3

Microsoft Outlook Remote Code Execution Vulnerability

CVE-2021-31941
HIGH 7.8

Microsoft Office Graphics Remote Code Execution Vulnerability

CVE-2021-31939
HIGH 7.8

Microsoft Excel Remote Code Execution Vulnerability

CVE-2021-1675
HIGH 7.8 KEV

Windows Print Spooler Remote Code Execution Vulnerability

CVE-2021-33742
CRITICAL · éditeur KEV

Windows MSHTML Platform Remote Code Execution Vulnerability

CVE-2021-33739
HIGH · éditeur KEV

Microsoft DWM Core Library Elevation of Privilege Vulnerability

CVE-2021-31977
HIGH · éditeur

Windows Hyper-V Denial of Service Vulnerability

CVE-2021-31976
HIGH · éditeur

Server for NFS Information Disclosure Vulnerability

CVE-2021-31975
HIGH · éditeur

Server for NFS Information Disclosure Vulnerability

CVE-2021-31974
HIGH · éditeur

Server for NFS Denial of Service Vulnerability

CVE-2021-31973
HIGH · éditeur

Windows GPSVC Elevation of Privilege Vulnerability

CVE-2021-31972
HIGH · éditeur

Event Tracing for Windows Information Disclosure Vulnerability

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa