Telegram records
37 published records for vendor telegram.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 21.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-863 Incorrect Authorization2
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')2
- CWE-287 Improper Authentication2
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-17613No exploit | Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKtelegram · telegram desktop · CWE-522 | Critical9.8 | — | 1.6% | Sep 28, 2018 |
39Monitor | CVE-2021-40532No exploit | Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.telegram · web k alpha | Critical9.8 | — | 1.3% | Sep 6, 2021 |
36Monitor | CVE-2019-10044No exploit | Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attatelegram · telegram | High8.8 | — | 3.3% | Mar 25, 2019 |
36Monitor | CVE-2017-17715No exploit | The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal vtelegram · telegram messenger · CWE-22 | High8.8 | — | 1.7% | Dec 16, 2017 |
32Monitor | CVE-2020-17448No exploit | Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstratedtelegram · telegram desktop · CWE-863 | High7.8 | — | 2.3% | Aug 11, 2020 |
32Monitor | CVE-2018-20436No exploit | The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed whiltelegram · telegram · CWE-918 | High8.1 | — | 1.6% | Dec 24, 2018 |
30Monitor | CVE-2018-17231No exploit | Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Etelegram · telegram desktop · CWE-617 | High7.5 | — | 1.5% | Sep 19, 2018 |
30Monitor | CVE-2014-8688No exploit | An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android.telegram · messenger · CWE-200 | High7.5 | — | 1.3% | Mar 14, 2017 |
28Monitor | CVE-2024-7014Proof of concept | Improper multimedia file attachment validation in Telegram for Android apptelegram · telegram · CWE-20 | High7.1 | — | 1.4% | Jul 23, 2024 |
28Monitor | CVE-2021-31320No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::gentelegram · telegram · CWE-787 | High7.1 | — | 1.2% | May 18, 2021 |
28Monitor | CVE-2021-31321No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic futelegram · telegram · CWE-787 | High7.1 | — | 1.1% | May 18, 2021 |
27Monitor | CVE-2020-12474No exploit | Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Puntelegram · telegram | Medium6.5 | — | 2.6% | May 1, 2020 |
27Monitor | CVE-2018-17780No exploit | Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call telegram · telegram desktop · CWE-200 | Medium6.5 | — | 1.8% | Sep 29, 2018 |
27Monitor | CVE-2018-15543No exploit | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.telegram · telegram · CWE-287 | Medium6.8 | — | 0.4% | Oct 9, 2018 |
25Monitor | CVE-2018-15542No exploit | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.telegram · telegram · CWE-287 | Medium6.4 | — | 0.3% | Oct 9, 2018 |
24Monitor | CVE-2021-37596No exploit | Telegram Web K Alpha 0.6.1 allows XSS via a document name.telegram · web k alpha · CWE-79 | Medium6.1 | — | 0.6% | Jul 30, 2021 |
24Monitor | CVE-2022-43363No exploit | Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website.telegram · telegram · CWE-79 | Medium6.1 | — | 0.4% | Dec 6, 2022 |
24Monitor | CVE-2020-10570No exploit | The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intendedtelegram · telegram | Medium6.1 | — | 0.4% | Mar 24, 2020 |
22Monitor | CVE-2019-15514Proof of concept | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Notelegram · telegram | Medium5.3 | — | 2.3% | Aug 23, 2019 |
22Monitor | CVE-2021-31322No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populatelegram · telegram · CWE-787 | Medium5.5 | — | 1.4% | May 18, 2021 |
22Monitor | CVE-2021-31319No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate telegram · telegram · CWE-190 | Medium5.5 | — | 1.3% | May 18, 2021 |
22Monitor | CVE-2021-31315No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of thtelegram · telegram · CWE-787 | Medium5.5 | — | 1.3% | May 18, 2021 |
22Monitor | CVE-2021-31317No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of thtelegram · telegram · CWE-843 | Medium5.5 | — | 1.3% | May 18, 2021 |
22Monitor | CVE-2021-31318No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTComptelegram · telegram · CWE-843 | Medium5.5 | — | 1.3% | May 18, 2021 |
22Monitor | CVE-2021-31323No exploit | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::ptelegram · telegram · CWE-787 | Medium5.5 | — | 1.3% | May 18, 2021 |
- CVE-2018-1761339Monitor
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCK
CriticalCVSS 9.8No exploitEPSS 2%telegram · telegram desktopSep 28, 2018
- CVE-2021-4053239Monitor
Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
CriticalCVSS 9.8No exploitEPSS 1%telegram · web k alphaSep 6, 2021
- CVE-2019-1004436Monitor
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph atta
HighCVSS 8.8No exploitEPSS 3%telegram · telegramMar 25, 2019
- CVE-2017-1771536Monitor
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal v
HighCVSS 8.8No exploitEPSS 2%telegram · telegram messengerDec 16, 2017
- CVE-2020-1744832Monitor
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated
HighCVSS 7.8No exploitEPSS 2%telegram · telegram desktopAug 11, 2020
- CVE-2018-2043632Monitor
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed whil
HighCVSS 8.1No exploitEPSS 2%telegram · telegramDec 24, 2018
- CVE-2018-1723130Monitor
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "E
HighCVSS 7.5No exploitEPSS 2%telegram · telegram desktopSep 19, 2018
- CVE-2014-868830Monitor
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android.
HighCVSS 7.5No exploitEPSS 1%telegram · messengerMar 14, 2017
- CVE-2024-701428Monitor
Improper multimedia file attachment validation in Telegram for Android app
HighCVSS 7.1Proof of conceptEPSS 1%telegram · telegramJul 23, 2024
- CVE-2021-3132028Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::gen
HighCVSS 7.1No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3132128Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic fu
HighCVSS 7.1No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2020-1247427Monitor
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Pun
MediumCVSS 6.5No exploitEPSS 3%telegram · telegramMay 1, 2020
- CVE-2018-1778027Monitor
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call
MediumCVSS 6.5No exploitEPSS 2%telegram · telegram desktopSep 29, 2018
- CVE-2018-1554327Monitor
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.
MediumCVSS 6.8No exploitEPSS 0%telegram · telegramOct 9, 2018
- CVE-2018-1554225Monitor
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.
MediumCVSS 6.4No exploitEPSS 0%telegram · telegramOct 9, 2018
- CVE-2021-3759624Monitor
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
MediumCVSS 6.1No exploitEPSS 1%telegram · web k alphaJul 30, 2021
- CVE-2022-4336324Monitor
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website.
MediumCVSS 6.1No exploitEPSS 0%telegram · telegramDec 6, 2022
- CVE-2020-1057024Monitor
The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended
MediumCVSS 6.1No exploitEPSS 0%telegram · telegramMar 24, 2020
- CVE-2019-1551422Monitor
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is No
MediumCVSS 5.3Proof of conceptEPSS 2%telegram · telegramAug 23, 2019
- CVE-2021-3132222Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::popula
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3131922Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3131522Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of th
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3131722Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of th
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3131822Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTComp
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021
- CVE-2021-3132322Monitor
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::p
MediumCVSS 5.5No exploitEPSS 1%telegram · telegramMay 18, 2021