Récap annuel
Sécurité des apps · 2023
Bilan 2023 indexé par Appaloosa Scout : 1 676 CVE publiées dans l'année sur les apps suivies, 49 ajoutées au catalogue CISA KEV (exploitées en réel), 13 apps affectées par au moins une KEV.
Voir les tendances pluriannuelles dans l'Observatoire des menaces
- CVE indexées dans l'année
- 1 676
- KEV CISA ajoutées
- 49
- Apps suivies touchées
- 13
Distribution par sévérité
CRITICAL
132
HIGH
1 306
MEDIUM
231
LOW
7
Top 10 KEV de l'année
Triées par sévérité CVSS. « Apps » compte les apps suivies du catalogue : beaucoup de KEV sont au niveau OS et affichent légitimement 0.
| CVE | Sévérité | Apps | Ajouté KEV | Description |
|---|---|---|---|---|
|
CVE-2023-23397
3 apps
|
CRITICAL 9.8 | 3 | 2023-03-14 | Microsoft Outlook Elevation of Privilege Vulnerability |
|
CVE-2023-6345
2 apps
|
CRITICAL 9.6 | 2 | 2023-11-30 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to pot… |
|
CVE-2023-2136
2 apps
|
CRITICAL 9.6 | 2 | 2023-04-21 | Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to pot… |
|
CVE-2023-5217
6 apps
|
HIGH 8.8 | 6 | 2023-10-02 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to pote… |
|
CVE-2023-4863
4 apps
|
HIGH 8.8 | 4 | 2023-09-13 | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of b… |
|
CVE-2023-35311
3 apps
|
HIGH 8.8 | 3 | 2023-07-11 | Microsoft Outlook Security Feature Bypass Vulnerability |
|
CVE-2023-3079
2 apps
|
HIGH 8.8 | 2 | 2023-06-07 | Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2023-2033
2 apps
|
HIGH 8.8 | 2 | 2023-04-17 | Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafte… |
|
CVE-2022-3038
2 apps
|
HIGH 8.8 | 2 | 2023-03-30 | Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption … |
|
CVE-2023-42917
0 apps
|
HIGH 8.8 | 0 | 2023-12-04 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14… |
Top vendors par KEV cette année
- 1 Google LLC 7 KEV · 1 apps
- 2 Microsoft Corporation 4 KEV · 3 apps
- 3 Mozilla 3 KEV · 3 apps
- 4 Microsoft 3 KEV · 1 apps
- 5 Microsoft Office 3 KEV · 1 apps
- 6 Adobe 2 KEV · 1 apps
- 7 Adobe Acrobat Reader 2 KEV · 1 apps
- 8 win.rar GmbH 1 KEV · 1 apps
Apps les plus affectées
Google Chrome
winget:Google.Chrome
Aucune vuln. ouverte
Chrome
com.google.Chrome
Aucune vuln. ouverte
Mozilla Thunderbird
winget:Mozilla.Thunderbird
Aucune vuln. ouverte
Mozilla Firefox
winget:Mozilla.Firefox
Aucune vuln. ouverte
Office
winget:Microsoft.Office
Aucune vuln. ouverte
Microsoft Office
brew:cask:microsoft-office
Aucune vuln. ouverte
Adobe Acrobat Reader (64-bit)
winget:Adobe.Acrobat.Reader.64-bit
Aucune vuln. ouverte
Microsoft Outlook
com.microsoft.Outlook
Aucune vuln. ouverte
Adobe Acrobat Reader
brew:cask:adobe-acrobat-reader
Aucune vuln. ouverte
WinRAR
winget:RARLab.WinRAR
Aucune vuln. ouverte
Méthodologie
KEV : ajoutées au catalogue CISA durant l'année (kev_added_date). CVE : date de publication NVD. Apps : celles indexées dans Scout au moment de la requête, l'historique évolue à chaque nouvel ajout au catalogue.