dropbox records
16 published records for vendor dropbox.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication3
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-1187 DEPRECATED: Use of Uninitialized Resource1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
- Dropbox Bug BountyIntigriti · paid · up to $15,000
- Dropbox Vulnerability Disclosure Program Intigriti · disclosure only (VDP)
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-4768No exploit | Dropbox merou SSH Public Key public_key.py add_public_key injectiondropbox · merou · CWE-74 | Critical9.8 | — | 0.7% | Dec 27, 2022 |
39Monitor | CVE-2024-25718No exploit | In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access dropbox · samly · CWE-613 | Critical9.8 | — | 0.7% | Feb 11, 2024 |
35Monitor | CVE-2024-5924No exploit | Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerabilitydropbox · dropbox desktop · CWE-693 | High8.8 | — | 1.2% | Jun 13, 2024 |
31Monitor | CVE-2018-20819No exploit | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffedropbox · lepton · CWE-787 | High7.8 | — | 1.0% | Apr 23, 2019 |
31Monitor | CVE-2019-12171No exploit | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memodropbox · dropbox · CWE-312 | High7.8 | — | 0.9% | Jul 8, 2019 |
31Monitor | CVE-2022-26181No exploit | Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:1dropbox · lepton · CWE-787 | High7.8 | — | 0.9% | Feb 28, 2022 |
27Monitor | CVE-2010-3354No exploit | dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trdropbox · dropbox | Medium6.9 | — | 0.3% | Oct 20, 2010 |
25Monitor | CVE-2026-28809No exploit | XXE in esaml SAML library allows local file read and potential SSRFarekinath · esaml · CWE-611 | Medium6.3 | — | 0.5% | Mar 23, 2026 |
25Monitor | CVE-2018-12271No exploit | An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS.dropbox · dropbox · CWE-287 | Medium6.4 | — | 0.4% | Jun 13, 2018 |
23Monitor | CVE-2014-8889No exploit | Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by downdropbox · dropbox sdk · CWE-200 | Medium5.3 | — | 5.8% | Sep 25, 2017 |
22Monitor | CVE-2017-7448No exploit | The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial ofdropbox · lepton · CWE-369 | Medium5.5 | — | 1.2% | Apr 5, 2017 |
22Monitor | CVE-2018-12108No exploit | An issue was discovered in Dropbox Lepton 1.2.1.dropbox · lepton · CWE-20 | Medium5.5 | — | 1.2% | Jun 11, 2018 |
22Monitor | CVE-2018-20820No exploit | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an intedropbox · lepton · CWE-190 | Medium5.5 | — | 1.0% | Apr 23, 2019 |
22Monitor | CVE-2017-8891No exploit | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correctdropbox · lepton · CWE-1187 | Medium5.5 | — | 0.9% | May 10, 2017 |
14Monitor | CVE-2018-12446No exploit | An issue was discovered in the com.dropbox.android application 98.2.2 for Android.dropbox · dropbox · CWE-287 | Low3.6 | — | 0.3% | Jun 20, 2018 |
12Monitor | CVE-2018-12445No exploit | An issue was discovered in the com.dropbox.android application 98.2.2 for Android.dropbox · dropbox · CWE-287 | Low3.1 | — | 0.3% | Jun 20, 2018 |
- CVE-2022-476839Monitor
Dropbox merou SSH Public Key public_key.py add_public_key injection
CriticalCVSS 9.8No exploitEPSS 1%dropbox · merouDec 27, 2022
- CVE-2024-2571839Monitor
In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access
CriticalCVSS 9.8No exploitEPSS 1%dropbox · samlyFeb 11, 2024
- CVE-2024-592435Monitor
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability
HighCVSS 8.8No exploitEPSS 1%dropbox · dropbox desktopJun 13, 2024
- CVE-2018-2081931Monitor
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffe
HighCVSS 7.8No exploitEPSS 1%dropbox · leptonApr 23, 2019
- CVE-2019-1217131Monitor
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memo
HighCVSS 7.8No exploitEPSS 1%dropbox · dropboxJul 8, 2019
- CVE-2022-2618131Monitor
Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:1
HighCVSS 7.8No exploitEPSS 1%dropbox · leptonFeb 28, 2022
- CVE-2010-335427Monitor
dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Tr
MediumCVSS 6.9No exploitEPSS 0%dropbox · dropboxOct 20, 2010
- CVE-2026-2880925Monitor
XXE in esaml SAML library allows local file read and potential SSRF
MediumCVSS 6.3No exploitEPSS 0%arekinath · esamlMar 23, 2026
- CVE-2018-1227125Monitor
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS.
MediumCVSS 6.4No exploitEPSS 0%dropbox · dropboxJun 13, 2018
- CVE-2014-888923Monitor
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by down
MediumCVSS 5.3No exploitEPSS 6%dropbox · dropbox sdkSep 25, 2017
- CVE-2017-744822Monitor
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of
MediumCVSS 5.5No exploitEPSS 1%dropbox · leptonApr 5, 2017
- CVE-2018-1210822Monitor
An issue was discovered in Dropbox Lepton 1.2.1.
MediumCVSS 5.5No exploitEPSS 1%dropbox · leptonJun 11, 2018
- CVE-2018-2082022Monitor
read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an inte
MediumCVSS 5.5No exploitEPSS 1%dropbox · leptonApr 23, 2019
- CVE-2017-889122Monitor
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct
MediumCVSS 5.5No exploitEPSS 1%dropbox · leptonMay 10, 2017
- CVE-2018-1244614Monitor
An issue was discovered in the com.dropbox.android application 98.2.2 for Android.
LowCVSS 3.6No exploitEPSS 0%dropbox · dropboxJun 20, 2018
- CVE-2018-1244512Monitor
An issue was discovered in the com.dropbox.android application 98.2.2 for Android.
LowCVSS 3.1No exploitEPSS 0%dropbox · dropboxJun 20, 2018