Vulnerability · NVD
CVE-2020-15502
CVE-2020-15502, high severity (CVSS 7.5): 2 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 7.5
- Exploitation
- 1.5 %
- Tracked apps
- 2
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
The DuckDuckGo application through 5.58.0 for Android, and through 7.47.1.0 for iOS, sends hostnames of visited web sites within HTTPS .ico requests to servers in the duckduckgo.com domain, which might make visit data available temporarily at a Potentially Unwanted Endpoint. NOTE: the vendor has stated "the favicon service adheres to our strict privacy policy.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (2)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| duckduckgo |
duckduckgo Android
|
Android | ≤5.58.0 | cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:android:*:* |
| duckduckgo |
duckduckgo iOS
|
iOS | ≤7.47.1.0 | cpe:2.3:a:duckduckgo:duckduckgo:*:*:*:*:*:iphone_os:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.