Skip to content
Noroxi

Telegram records

37 published records for vendor telegram.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
21.6%
Median publish → KEV
No record has entered KEV

All records

37 records
  • Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCK

    CriticalCVSS 9.8No exploitEPSS 2%

    telegram · telegram desktopSep 28, 2018

  • Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.

    CriticalCVSS 9.8No exploitEPSS 1%

    telegram · web k alphaSep 6, 2021

  • Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph atta

    HighCVSS 8.8No exploitEPSS 3%

    telegram · telegramMar 25, 2019

  • The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal v

    HighCVSS 8.8No exploitEPSS 2%

    telegram · telegram messengerDec 16, 2017

  • Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated

    HighCVSS 7.8No exploitEPSS 2%

    telegram · telegram desktopAug 11, 2020

  • The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed whil

    HighCVSS 8.1No exploitEPSS 2%

    telegram · telegramDec 24, 2018

  • Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "E

    HighCVSS 7.5No exploitEPSS 2%

    telegram · telegram desktopSep 19, 2018

  • CVE-2014-8688
    30Monitor

    An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android.

    HighCVSS 7.5No exploitEPSS 1%

    telegram · messengerMar 14, 2017

  • CVE-2024-7014
    28Monitor

    Improper multimedia file attachment validation in Telegram for Android app

    HighCVSS 7.1Proof of conceptEPSS 1%

    telegram · telegramJul 23, 2024

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::gen

    HighCVSS 7.1No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic fu

    HighCVSS 7.1No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Pun

    MediumCVSS 6.5No exploitEPSS 3%

    telegram · telegramMay 1, 2020

  • Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call

    MediumCVSS 6.5No exploitEPSS 2%

    telegram · telegram desktopSep 29, 2018

  • An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.

    MediumCVSS 6.8No exploitEPSS 0%

    telegram · telegramOct 9, 2018

  • An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.

    MediumCVSS 6.4No exploitEPSS 0%

    telegram · telegramOct 9, 2018

  • Telegram Web K Alpha 0.6.1 allows XSS via a document name.

    MediumCVSS 6.1No exploitEPSS 1%

    telegram · web k alphaJul 30, 2021

  • Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website.

    MediumCVSS 6.1No exploitEPSS 0%

    telegram · telegramDec 6, 2022

  • The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended

    MediumCVSS 6.1No exploitEPSS 0%

    telegram · telegramMar 24, 2020

  • The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is No

    MediumCVSS 5.3Proof of conceptEPSS 2%

    telegram · telegramAug 23, 2019

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::popula

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of th

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of th

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTComp

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021

  • Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::p

    MediumCVSS 5.5No exploitEPSS 1%

    telegram · telegramMay 18, 2021