Skip to content
Appaloosa Scout
Language selector
fr en

Vulnerability · NVD

CVE-2020-15502

CVE-2020-15502, high severity (CVSS 7.5): 2 tracked apps concerned, all fixed or indeterminable on their current version.

Severity (CVSS)
7.5

NVD scale

Exploitation
1.5 %

EPSS, predicted over 30 days

Tracked apps
2
Still exposed
0

The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.

Attack vector : Network No privileges required No user interaction
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS 1.53% above median percentile 73.7%

Tracked apps referencing this CVE

For each app: the affected range, the fixing version, and where the tracked app stands today.

  • DuckDuckGo Android com.duckduckgo.mobile.android
    Affected ≤5.58.0 Fixed in > 5.58.0 Latest tracked 5.295.3 patched
    Observed affected builds (2)
  • DuckDuckGo iOS com.duckduckgo.mobile.ios
    Affected ≤7.47.1.0 Fixed in > 7.47.1.0 Latest tracked 7.238.0 patched
Vulnerable CPE configurations (2)
Vendor Product Versions
duckduckgo duckduckgo
Android
≤5.58.0
duckduckgo duckduckgo
iOS
≤7.47.1.0
View on NVD ↗ Advisory · github.com Advisory · news.ycombinator.com

Manage your fleet with Appaloosa

Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.

Discover Appaloosa MDM