Skip to content
Noroxi

wire records

29 published records for vendor wire.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

29 records
  • Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a for

    CriticalCVSS 9.8No exploitEPSS 4%

    wire · wireOct 27, 2020

  • Use of Externally-Controlled Format String in wire-avs

    CriticalCVSS 9.8No exploitEPSS 2%

    wire · wire-audio video signalingMar 1, 2022

  • Account takeover when having only access to a user's short lived token

    CriticalCVSS 9.8No exploitEPSS 1%

    wire · wireOct 4, 2021

  • Account takeover when having only access to a user's short lived token in wire-server

    CriticalCVSS 9.8No exploitEPSS 1%

    wire · wire-serverOct 4, 2021

  • Unsafe loopback forwarding interface in Restund

    CriticalCVSS 9.6No exploitEPSS 1%

    wire · restundJun 11, 2021

  • wire-avs remote format string vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    wire · audio\, video\, and signalingNov 20, 2023

  • Insecure use of shell.openExternal in Wire

    HighCVSS 8.0No exploitEPSS 2%

    wire · wireOct 16, 2020

  • Improper Verification of Cryptographic Signature in wire-server

    HighCVSS 8.1No exploitEPSS 1%

    wire · wire-serverMar 16, 2022

  • Wire-server vulnerable to Token Recipient Confusion resulting in account impersonation, deletion or malicious account creation

    HighCVSS 8.1No exploitEPSS 1%

    wire · wire serverOct 18, 2022

  • CVE-2018-8909
    30Monitor

    The Wire application before 2018-03-07 for Android allows attackers to write to pathnames outside of the downloads directory via a ../ in a

    HighCVSS 7.5No exploitEPSS 2%

    wire · wireMar 22, 2018

  • DoS vulnerabiliity in wire-server json parser

    HighCVSS 7.5No exploitEPSS 1%

    wire · wire-serverApr 13, 2022

  • DoS vulnerability: Malformed Resource Identifiers

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wireMar 11, 2022

  • Entering code in App Lock modal sends input to conversation

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wire-webappApr 2, 2021

  • Bulk list client endpoint exposes too much metadata about a client

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wire serverMar 26, 2021

  • Asset DoS vulnerability

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wireJun 3, 2021

  • wire-server vulnerable to unauthorized removal of Bots from Conversations

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wireJan 27, 2023

  • DoS vulnerability: Invalid Accent Colors

    MediumCVSS 6.5No exploitEPSS 1%

    wire · wireJun 23, 2022

  • Verified groups not reliable

    MediumCVSS 6.5No exploitEPSS 0%

    wire · wireJun 3, 2021

  • Cross Site Scripting in Wire Webapp

    MediumCVSS 6.1No exploitEPSS 1%

    wire · wire-webappApr 20, 2022

  • Cross Site Scripting in Wire Messages

    MediumCVSS 6.1No exploitEPSS 1%

    wire · wire-webappJun 25, 2022

  • XSS through createObjectURL

    MediumCVSS 6.1No exploitEPSS 1%

    wire · wire-webappJun 15, 2021

  • CORS `Access-Control-Allow-Origin` settings are too lenient

    MediumCVSS 5.7No exploitEPSS 1%

    wire · wire serverSep 30, 2021

  • wire-webapp has no database deletion on client logout

    MediumCVSS 5.5No exploitEPSS 0%

    wire · wire-webappMay 22, 2025

  • wire-webapp contains Improper Handling of Exceptional Conditions leading to a DoS via Markdown Rendering

    MediumCVSS 5.3No exploitEPSS 1%

    wire · wire-webappJan 27, 2023

  • Wire through 3.22.3993 on Windows advertises deletion of sent messages; nonetheless, all messages can be retrieved (for a limited period of

    MediumCVSS 4.7No exploitEPSS 0%

    wire · wireNov 18, 2022