Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilités

Vulnérabilités des apps suivies

25 753 CVE touchent une app ou un OS suivi (toutes sévérités, toutes plateformes). 372 figurent au catalogue CISA KEV, donc leur exploitation est avérée.

CVE correspondantes
25 753
Activement exploitées
372
Fenêtre de publication
1997-01-01 → 2026-09-17

Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.

25 753 entrées
CVE
CVE-2026-0095
HIGH 8.0

In l2c_fcr_clone_buf of l2c_fcr.cc, there is a possible way to trigger controlled heap corruption within the privileged Bluetooth process due to an integer ove…

CVE-2026-0094
HIGH 7.8

In getApplicationLabel of KeyChainActivity.java, there is a possible way to trick the user into approving access to certificates due to misleading or insuffici…

CVE-2026-0093
HIGH 7.8

In multiple locations, there is a possible misleading UI due to obfuscation. This could lead to local escalation of privilege with no additional execution priv…

CVE-2026-0091
HIGH 7.8

In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell user. This could lead to local escalatio…

CVE-2026-0089
HIGH 7.8

In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missing permission check. This could lead to…

CVE-2026-0088
HIGH 7.8

In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to misleading or insufficient UI. This could lea…

CVE-2026-0087
HIGH 7.8

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. …

CVE-2026-0086
MEDIUM 6.8

In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalati…

CVE-2026-0085
MEDIUM 5.5

In applySimpleFieldMaxSize of DataRowHandler.java, there is a possible way to insert a large contact name due to improper input validation. This could lead to …

CVE-2026-0080
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0079
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local deni…

CVE-2026-0078
HIGH 7.8

In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local esca…

CVE-2026-0077
HIGH 7.8

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lea…

CVE-2026-0076
HIGH 7.8

In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege…

CVE-2026-0075
MEDIUM 5.9

In multiple functions, there is a possible way to access the contacts database due to a SQL injection. This could lead to local escalation of privilege with no…

CVE-2026-0074
MEDIUM 5.5

In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of s…

CVE-2026-0070
MEDIUM 5.5

In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This coul…

CVE-2026-0069
MEDIUM 5.5

In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with n…

CVE-2026-0067
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This coul…

CVE-2026-0061
MEDIUM 5.9

In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could l…

CVE-2026-0060
MEDIUM 5.5

In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lea…

CVE-2026-0059
HIGH 8.0

In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal…

CVE-2026-0056
LOW 3.3

In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no…

CVE-2026-0055
MEDIUM 6.2

In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a pat…

CVE-2026-0052
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0051
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remot…

CVE-2026-0050
LOW 3.3

In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local in…

CVE-2026-0048
MEDIUM 6.8

In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local …

CVE-2026-0046
MEDIUM 6.2

In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead …

CVE-2026-0045
HIGH 7.8

In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to l…

CVE-2026-0044
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote…

CVE-2026-0043
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local esca…

CVE-2026-0042
MEDIUM 5.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local deni…

CVE-2026-0041
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service …

CVE-2026-0040
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of s…

CVE-2026-0039
MEDIUM 6.5

In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote den…

CVE-2026-0036
HIGH 7.8

In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of pri…

CVE-2026-0018
MEDIUM 5.5

In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead t…

CVE-2026-0016
LOW 3.3

In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. T…

CVE-2026-0009
HIGH 7.8

In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalation of privilege with no additional exe…

CVE-2025-48652
HIGH 7.8

In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local esc…

CVE-2025-48649
HIGH 7.8

In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation o…

CVE-2025-48648
MEDIUM 5.5

In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with…

CVE-2025-48616
LOW 3.3

In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This…

CVE-2025-48595
HIGH 8.4 KEV

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no a…

CVE-2025-48570
HIGH 7.8

In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to …

CVE-2025-32348
HIGH 7.8

In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with …

CVE-2025-26418
HIGH 7.8

In setUserDisclaimerAcknowledged of CarDevicePolicyService.java, there is a possible way to bypass the user dialog when adding an account to a managed device d…

CVE-2025-22426
HIGH 7.8

In many functions of ComputerEngine.java, there is a possible way to access URIs across users due to a logic error in the code. This could lead to local escala…

CVE-2025-22424
HIGH 7.8

In multiple locations, there is a possible way to reveal images across users due to improper input validation. This could lead to local escalation of privilege…

Gérez votre parc avec Appaloosa

Appaloosa pousse mises à jour d'OS, apps et politiques sur vos appareils Windows, macOS, iOS et Android depuis une seule console.

Découvrir le MDM Appaloosa