Skip to content
Noroxi

dropbox records

16 published records for vendor dropbox.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
12.5%
Median publish → KEV
No record has entered KEV

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

16 records
  • CVE-2022-4768
    39Monitor

    Dropbox merou SSH Public Key public_key.py add_public_key injection

    CriticalCVSS 9.8No exploitEPSS 1%

    dropbox · merouDec 27, 2022

  • In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access

    CriticalCVSS 9.8No exploitEPSS 1%

    dropbox · samlyFeb 11, 2024

  • CVE-2024-5924
    35Monitor

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    dropbox · dropbox desktopJun 13, 2024

  • io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffe

    HighCVSS 7.8No exploitEPSS 1%

    dropbox · leptonApr 23, 2019

  • Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memo

    HighCVSS 7.8No exploitEPSS 1%

    dropbox · dropboxJul 8, 2019

  • Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:1

    HighCVSS 7.8No exploitEPSS 1%

    dropbox · leptonFeb 28, 2022

  • CVE-2010-3354
    27Monitor

    dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Tr

    MediumCVSS 6.9No exploitEPSS 0%

    dropbox · dropboxOct 20, 2010

  • XXE in esaml SAML library allows local file read and potential SSRF

    MediumCVSS 6.3No exploitEPSS 0%

    arekinath · esamlMar 23, 2026

  • An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS.

    MediumCVSS 6.4No exploitEPSS 0%

    dropbox · dropboxJun 13, 2018

  • CVE-2014-8889
    23Monitor

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by down

    MediumCVSS 5.3No exploitEPSS 6%

    dropbox · dropbox sdkSep 25, 2017

  • CVE-2017-7448
    22Monitor

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of

    MediumCVSS 5.5No exploitEPSS 1%

    dropbox · leptonApr 5, 2017

  • An issue was discovered in Dropbox Lepton 1.2.1.

    MediumCVSS 5.5No exploitEPSS 1%

    dropbox · leptonJun 11, 2018

  • read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an inte

    MediumCVSS 5.5No exploitEPSS 1%

    dropbox · leptonApr 23, 2019

  • CVE-2017-8891
    22Monitor

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct

    MediumCVSS 5.5No exploitEPSS 1%

    dropbox · leptonMay 10, 2017

  • An issue was discovered in the com.dropbox.android application 98.2.2 for Android.

    LowCVSS 3.6No exploitEPSS 0%

    dropbox · dropboxJun 20, 2018

  • An issue was discovered in the com.dropbox.android application 98.2.2 for Android.

    LowCVSS 3.1No exploitEPSS 0%

    dropbox · dropboxJun 20, 2018