Twitter kayıtları
twitter üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-295 Improper Certificate Validation2
- CWE-310 Cryptographic Issues1
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
- CWE-360 Trust of System Event Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2020-35774Kavram kanıtı | server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS twitter · twitter-server · CWE-79 | Orta5,4 | — | %85,6 | 29 Ara 2020 |
30İzleyin | CVE-2023-29218İstismar yok | The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrangtwitter · recommendation algorithm | Yüksek7,5 | — | %1,1 | 3 Nis 2023 |
29İzleyin | CVE-2019-16263İstismar yok | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.twitter · twitter kit · CWE-295 | Yüksek7,4 | — | %1,0 | 7 Eki 2019 |
24İzleyin | CVE-2020-5217İstismar yok | Directive injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-95 | Orta5,8 | — | %1,8 | 22 Oca 2020 |
23İzleyin | CVE-2020-5216İstismar yok | Limited header injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-113 | Orta5,8 | — | %1,1 | 22 Oca 2020 |
23İzleyin | CVE-2016-10511İstismar yok | The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configurationtwitter · twitter · CWE-295 | Orta5,9 | — | %0,8 | 18 Eyl 2017 |
21İzleyin | CVE-2017-0911İstismar yok | Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attwitter · twitter kit · CWE-360 | Orta5,4 | — | %0,5 | 9 Şub 2018 |
21İzleyin | CVE-2019-5431İstismar yok | This vulnerability was caused by an incomplete fix to CVE-2017-0911.twitter · twitter kit · CWE-352 | Orta5,4 | — | %0,4 | 6 May 2019 |
21İzleyin | CVE-2014-6838İstismar yok | The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, whtwitter · groupama toujours la · CWE-310 | Orta5,4 | — | %0,3 | 30 Eyl 2014 |
- CVE-2020-3577447Planlayın
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS
OrtaCVSS 5,4Kavram kanıtıEPSS %86twitter · twitter-server29 Ara 2020
- CVE-2023-2921830İzleyin
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrang
YüksekCVSS 7,5İstismar yokEPSS %1twitter · recommendation algorithm3 Nis 2023
- CVE-2019-1626329İzleyin
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.
YüksekCVSS 7,4İstismar yokEPSS %1twitter · twitter kit7 Eki 2019
- CVE-2020-521724İzleyin
Directive injection when using dynamic overrides with user input in RubyGems secure_headers
OrtaCVSS 5,8İstismar yokEPSS %2twitter · secure headers22 Oca 2020
- CVE-2020-521623İzleyin
Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
OrtaCVSS 5,8İstismar yokEPSS %1twitter · secure headers22 Oca 2020
- CVE-2016-1051123İzleyin
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration
OrtaCVSS 5,9İstismar yokEPSS %1twitter · twitter18 Eyl 2017
- CVE-2017-091121İzleyin
Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an at
OrtaCVSS 5,4İstismar yokEPSS %1twitter · twitter kit9 Şub 2018
- CVE-2019-543121İzleyin
This vulnerability was caused by an incomplete fix to CVE-2017-0911.
OrtaCVSS 5,4İstismar yokEPSS %0twitter · twitter kit6 May 2019
- CVE-2014-683821İzleyin
The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, wh
OrtaCVSS 5,4İstismar yokEPSS %0twitter · groupama toujours la30 Eyl 2014