Vulnerabilities
Tracked app vulnerabilities
545 entries
Chronological sort: newest to oldest. Use the KEV / severity filters above to prioritize.
| CVE |
|---|
|
CVE-2022-25375
MEDIUM 5.5
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-25258
MEDIUM 4.6
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-39700
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-26558
MEDIUM 4.2
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2020-20096
MEDIUM 6.5
Network 2 apps
Whatsapp iOS 2.19.80 and prior and Android 2.19.222 and prior user interface does not properly represent URI messages to the user, which results in URI spoofin… |
|
CVE-2021-39689
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2022-23255
MEDIUM 5.9
Physical 1 apps
Microsoft OneDrive for Android Security Feature Bypass Vulnerability |
|
CVE-2021-0969
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0961
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0958
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0922
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0919
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-0691
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-38204
MEDIUM 6.8
drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) … |
|
CVE-2021-36769
MEDIUM 5.3
Network 2 apps
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the ser… |
|
CVE-2021-31323
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty fu… |
|
CVE-2021-31322
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of thei… |
|
CVE-2021-31319
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their c… |
|
CVE-2021-31318
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function … |
|
CVE-2021-31317
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of … |
|
CVE-2021-31315
MEDIUM 5.5
Local 2 apps
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of … |
|
CVE-2020-26146
MEDIUM 5.3
Adjacent network
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numb… |
|
CVE-2021-1906
MEDIUM
KEV
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2021-1467
MEDIUM 4.3
Network 1 apps
A vulnerability in Cisco Webex Meetings for Android could allow an authenticated, remote attacker to modify the avatar of another user. This vulnerability is d… |
|
CVE-2021-24100
MEDIUM 5.0
Local 1 apps
Microsoft Edge for Android Information Disclosure Vulnerability |
|
CVE-2021-27205
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure. |
|
CVE-2021-27204
MEDIUM 5.5
Local 2 apps
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. |
|
CVE-2020-15358
MEDIUM 5.5
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2021-23253
MEDIUM 5.3
Network 1 apps
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g.… |
|
CVE-2020-6159
MEDIUM 6.1
Network 1 apps
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain ci… |
|
CVE-2020-0500
MEDIUM 5.5
Local
In startInputUncheckedLocked of InputMethodManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local informa… |
|
CVE-2020-17153
MEDIUM 4.3
Network 1 apps
Microsoft Edge for Android Spoofing Vulnerability |
|
CVE-2020-29660
MEDIUM 4.4
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may al… |
|
CVE-2020-24441
MEDIUM 5.5
Local 1 apps
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in… |
|
CVE-2020-15436
MEDIUM 6.7
Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging … |
|
CVE-2020-0415
MEDIUM 5.5
Local
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of cont… |
|
CVE-2019-2194
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-12464
MEDIUM 6.7
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2020-10768
MEDIUM 5.5
A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function where it can be used to enable indirect branch speculation after it has been disabl… |
|
CVE-2020-10767
MEDIUM 5.5
A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will b… |
|
CVE-2020-10766
MEDIUM 5.5
A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to… |
|
CVE-2017-8246
MEDIUM 7.8
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2020-8647
MEDIUM 6.1
Microsoft Security Update Guide entry — NVD enrichira. |
|
CVE-2020-5753
MEDIUM 5.3
Network 1 apps
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used… |
|
CVE-2020-12474
MEDIUM 6.5
Network 2 apps
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public U… |
|
CVE-2020-0104
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0077
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-0075
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2019-9936
MEDIUM
Indexed via Android Security Bulletin; full NVD metadata pending. |
|
CVE-2020-10570
MEDIUM 6.1
Physical 1 apps
The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on me… |