intercom records
8 published records for vendor intercom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication2
- CWE-295 Improper Certificate Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-798 Use of Hard-coded Credentials1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-10817No exploit | MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.intercom · malion · CWE-287 | Critical9.8 | — | 3.1% | Aug 4, 2017 |
40Plan | CVE-2017-10816No exploit | SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Rintercom · malion · CWE-89 | Critical9.8 | — | 2.2% | Aug 4, 2017 |
40Plan | CVE-2017-10818No exploit | MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection seintercom · malion · CWE-798 | Critical9.8 | — | 1.8% | Aug 4, 2017 |
33Monitor | CVE-2017-10815No exploit | MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"intercom · malion · CWE-287 | High8.1 | — | 2.3% | Aug 4, 2017 |
31Monitor | CVE-2019-14365No exploit | The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.intercom · intercom · CWE-200 | High7.5 | — | 1.9% | Nov 12, 2019 |
27Monitor | CVE-2014-3881No exploit | Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authenticintercom · web kyukincho · CWE-352 | Medium6.8 | — | 0.6% | Jun 27, 2014 |
23Monitor | CVE-2017-10819No exploit | MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatiointercom · malion · CWE-295 | Medium5.9 | — | 0.8% | Aug 4, 2017 |
17Monitor | CVE-2014-2006No exploit | Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web scriptintercom · web kyukincho · CWE-79 | Medium4.3 | — | 1.1% | Jun 27, 2014 |
- CVE-2017-1081740Plan
MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.
CriticalCVSS 9.8No exploitEPSS 3%intercom · malionAug 4, 2017
- CVE-2017-1081640Plan
SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via R
CriticalCVSS 9.8No exploitEPSS 2%intercom · malionAug 4, 2017
- CVE-2017-1081840Plan
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection se
CriticalCVSS 9.8No exploitEPSS 2%intercom · malionAug 4, 2017
- CVE-2017-1081533Monitor
MaLion for Windows 5.2.1 and earlier (only when "Remote Control" is installed) and MaLion for Mac 4.0.1 to 5.2.1 (only when "Remote Control"
HighCVSS 8.1No exploitEPSS 2%intercom · malionAug 4, 2017
- CVE-2019-1436531Monitor
The Intercom plugin through 1.2.1 for WordPress leaks a Slack Access Token in source code.
HighCVSS 7.5No exploitEPSS 2%intercom · intercomNov 12, 2019
- CVE-2014-388127Monitor
Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentic
MediumCVSS 6.8No exploitEPSS 1%intercom · web kyukinchoJun 27, 2014
- CVE-2017-1081923Monitor
MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communicatio
MediumCVSS 5.9No exploitEPSS 1%intercom · malionAug 4, 2017
- CVE-2014-200617Monitor
Cross-site scripting (XSS) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3No exploitEPSS 1%intercom · web kyukinchoJun 27, 2014