Récap annuel
Sécurité des apps · 2022
Bilan 2022 indexé par Appaloosa Scout : 1 649 CVE publiées dans l'année sur les apps suivies, 33 ajoutées au catalogue CISA KEV (exploitées en réel), 3 apps affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 1 649
- KEV CISA ajoutées
- 33
- Apps suivies touchées
- 3
Distribution par sévérité
CRITICAL
127
HIGH
1 324
MEDIUM
196
LOW
2
Top 10 KEV de l'année
Triées par sévérité CVSS. « Apps » compte les apps suivies du catalogue : beaucoup de KEV sont au niveau OS et affichent légitimement 0.
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2019-11708
2 apps
|
CRITICAL 10.0 | 2 | 2022-05-23 | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandbox… |
|
CVE-2020-0796
0 apps
|
CRITICAL 10.0 | 0 | 2022-02-10 | A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requ… |
|
CVE-2021-31166
0 apps
|
CRITICAL 9.8 | 0 | 2022-04-06 | HTTP Protocol Stack Remote Code Execution Vulnerability |
|
CVE-2022-4135
3 apps
|
CRITICAL 9.6 | 3 | 2022-11-28 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to … |
|
CVE-2022-3075
2 apps
|
CRITICAL 9.6 | 2 | 2022-09-08 | Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer pr… |
|
CVE-2022-26486
0 apps
|
CRITICAL 9.6 | 0 | 2022-03-07 | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of att… |
|
CVE-2019-1297
3 apps
|
HIGH 8.8 | 3 | 2022-03-03 | A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka … |
|
CVE-2022-4262
2 apps
|
HIGH 8.8 | 2 | 2022-12-05 | Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted… |
|
CVE-2022-3723
2 apps
|
HIGH 8.8 | 2 | 2022-10-28 | Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted… |
|
CVE-2022-2294
2 apps
|
HIGH 8.8 | 2 | 2022-08-25 | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption vi… |
Top vendors par KEV cette année
- 1 Google LLC 10 KEV · 1 apps
- 2 Microsoft Corporation 9 KEV · 3 apps
- 3 Microsoft 5 KEV · 1 apps
- 4 Mozilla 4 KEV · 2 apps
- 5 Microsoft Office 3 KEV · 1 apps
- 6 WhatsApp Inc. 1 KEV · 1 apps
- 7 win.rar GmbH 1 KEV · 1 apps
Apps les plus affectées
Google Chrome
winget:Google.Chrome
Aucune vuln. ouverte
Chrome
com.google.Chrome
Aucune vuln. ouverte
Office
winget:Microsoft.Office
Aucune vuln. ouverte
Microsoft Edge
winget:Microsoft.Edge
Aucune vuln. ouverte
Mozilla Thunderbird
winget:Mozilla.Thunderbird
Aucune vuln. ouverte
Mozilla Firefox
winget:Mozilla.Firefox
Aucune vuln. ouverte
Microsoft Office
brew:cask:microsoft-office
Aucune vuln. ouverte
Microsoft Word
com.microsoft.Word
Aucune vuln. ouverte
Microsoft Excel
com.microsoft.Excel
Aucune vuln. ouverte
WinRAR
winget:RARLab.WinRAR
Aucune vuln. ouverte
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête, l'historique évolue à chaque nouvel ajout au catalogue.