linecorp records
93 published records for vendor linecorp.
Researcher profile
- Entered KEV
- 1 · 1.1%
- Weaponized
- 1 · 1.1%
- Pre-auth RCE
- 3
- With a fix record
- 7.5%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor20
- CWE-326 Inadequate Encryption Strength10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-451 User Interface (UI) Misrepresentation of Critical Information5
- CWE-269 Improper Privilege Management4
- CWE-295 Improper Certificate Validation4
The weakness classes this vendor ships most often: where to look.
CWEAll records
93 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
39Monitor | CVE-2023-5554No exploit | Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.linecorp · line · CWE-295 | Critical9.8 | — | 0.2% | Oct 12, 2023 |
36Monitor | CVE-2019-6007No exploit | Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arlinecorp · apng-drawable · CWE-190 | High8.8 | — | 2.0% | Sep 12, 2019 |
36Monitor | CVE-2024-1735No exploit | A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentlinecorp · armeria · CWE-287 | Critical9.1 | — | 0.8% | Feb 26, 2024 |
35Monitor | CVE-2021-38388No exploit | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the linecorp · central dogma · CWE-862 | High8.8 | — | 0.9% | Sep 8, 2021 |
33Monitor | CVE-2016-4850No exploit | LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.linecorp · line · CWE-284 | High8.1 | — | 2.2% | Apr 20, 2017 |
32Monitor | CVE-2019-6010No exploit | Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of servicelinecorp · line · CWE-190 | High7.8 | — | 1.7% | Sep 19, 2019 |
32Monitor | CVE-2023-39739No exploit | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted brlinecorp · regina sweets\&bakery · CWE-200 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-39735No exploit | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadlinecorp · uomasa saiji new · CWE-200 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-39736No exploit | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted brlinecorp · fukunaga memberscard · CWE-200 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-39737No exploit | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messalinecorp · matsuya · CWE-200 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-39734No exploit | The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token anlinecorp · trackdiner10\/10 mc · CWE-269 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-43301No exploit | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel aclinecorp · line · CWE-94 | High8.2 | — | 0.6% | Dec 7, 2023 |
32Monitor | CVE-2023-43302No exploit | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tokenlinecorp · line | High8.2 | — | 0.6% | Dec 7, 2023 |
32Monitor | CVE-2023-39740No exploit | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadlinecorp · onigiriya-musubee · CWE-269 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-39732No exploit | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broalinecorp · tokueimaru waiting · CWE-269 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-43305No exploit | An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access linecorp · line | High8.2 | — | 0.6% | Dec 7, 2023 |
32Monitor | CVE-2023-39733No exploit | The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mlinecorp · tonton-tei · CWE-269 | High8.2 | — | 0.6% | Oct 25, 2023 |
32Monitor | CVE-2023-43304No exploit | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access linecorp · line · CWE-290 | High8.2 | — | 0.5% | Dec 7, 2023 |
32Monitor | CVE-2023-43300No exploit | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceslinecorp · line | High8.2 | — | 0.5% | Dec 7, 2023 |
32Monitor | CVE-2023-43303No exploit | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelinecorp · line | High8.2 | — | 0.5% | Dec 7, 2023 |
32Monitor | CVE-2023-45559No exploit | An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.linecorp · line | High8.2 | — | 0.5% | Jan 3, 2024 |
31Monitor | CVE-2021-43795No exploit | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in com.linecorp.armeria:armerialinecorp · armeria · CWE-22 | High7.5 | — | 1.7% | Dec 2, 2021 |
31Monitor | CVE-2018-0609No exploit | Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL ilinecorp · line · CWE-426 | High7.8 | — | 0.8% | Jun 26, 2018 |
31Monitor | CVE-2022-29505No exploit | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilegelinecorp · line | High7.8 | — | 0.5% | Apr 27, 2022 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2023-555439Monitor
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
CriticalCVSS 9.8No exploitEPSS 0%linecorp · lineOct 12, 2023
- CVE-2019-600736Monitor
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute ar
HighCVSS 8.8No exploitEPSS 2%linecorp · apng-drawableSep 12, 2019
- CVE-2024-173536Monitor
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authent
CriticalCVSS 9.1No exploitEPSS 1%linecorp · armeriaFeb 26, 2024
- CVE-2021-3838835Monitor
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the
HighCVSS 8.8No exploitEPSS 1%linecorp · central dogmaSep 8, 2021
- CVE-2016-485033Monitor
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
HighCVSS 8.1No exploitEPSS 2%linecorp · lineApr 20, 2017
- CVE-2019-601032Monitor
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service
HighCVSS 7.8No exploitEPSS 2%linecorp · lineSep 19, 2019
- CVE-2023-3973932Monitor
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted br
HighCVSS 8.2No exploitEPSS 1%linecorp · regina sweets\&bakeryOct 25, 2023
- CVE-2023-3973532Monitor
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broad
HighCVSS 8.2No exploitEPSS 1%linecorp · uomasa saiji newOct 25, 2023
- CVE-2023-3973632Monitor
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted br
HighCVSS 8.2No exploitEPSS 1%linecorp · fukunaga memberscardOct 25, 2023
- CVE-2023-3973732Monitor
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messa
HighCVSS 8.2No exploitEPSS 1%linecorp · matsuyaOct 25, 2023
- CVE-2023-3973432Monitor
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token an
HighCVSS 8.2No exploitEPSS 1%linecorp · trackdiner10\/10 mcOct 25, 2023
- CVE-2023-4330132Monitor
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel ac
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-4330232Monitor
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-3974032Monitor
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broad
HighCVSS 8.2No exploitEPSS 1%linecorp · onigiriya-musubeeOct 25, 2023
- CVE-2023-3973232Monitor
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broa
HighCVSS 8.2No exploitEPSS 1%linecorp · tokueimaru waitingOct 25, 2023
- CVE-2023-4330532Monitor
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-3973332Monitor
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m
HighCVSS 8.2No exploitEPSS 1%linecorp · tonton-teiOct 25, 2023
- CVE-2023-4330432Monitor
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-4330032Monitor
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acces
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-4330332Monitor
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channe
HighCVSS 8.2No exploitEPSS 1%linecorp · lineDec 7, 2023
- CVE-2023-4555932Monitor
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
HighCVSS 8.2No exploitEPSS 0%linecorp · lineJan 3, 2024
- CVE-2021-4379531Monitor
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in com.linecorp.armeria:armeria
HighCVSS 7.5No exploitEPSS 2%linecorp · armeriaDec 2, 2021
- CVE-2018-060931Monitor
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL i
HighCVSS 7.8No exploitEPSS 1%linecorp · lineJun 26, 2018
- CVE-2022-2950531Monitor
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege
HighCVSS 7.8No exploitEPSS 0%linecorp · lineApr 27, 2022