Vulnerability · NVD
CVE-2019-10044
CVE-2019-10044, high severity (CVSS 8.8): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 8.8
- Exploitation
- 3.3 %
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| telegram |
telegram All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:* |
| telegram |
telegram All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.