mailvelope records
4 published records for vendor mailvelope.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames1
- CWE-295 Improper Certificate Validation1
- CWE-320 Key Management Errors1
- CWE-347 Improper Verification of Cryptographic Signature1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2019-9149No exploit | Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API.mailvelope · mailvelope · CWE-347 | Medium6.5 | — | 0.9% | Jul 9, 2019 |
21Monitor | CVE-2019-9150No exploit | Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page.mailvelope · mailvelope · CWE-320 | Medium5.3 | — | 1.4% | Jul 9, 2019 |
17Monitor | CVE-2019-9147No exploit | Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page.mailvelope · mailvelope · CWE-1021 | Medium4.3 | — | 1.4% | Jul 9, 2019 |
17Monitor | CVE-2019-9148No exploit | Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a vamailvelope · mailvelope · CWE-295 | Medium4.3 | — | 1.4% | Jul 9, 2019 |
- CVE-2019-914926Monitor
Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API.
MediumCVSS 6.5No exploitEPSS 1%mailvelope · mailvelopeJul 9, 2019
- CVE-2019-915021Monitor
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page.
MediumCVSS 5.3No exploitEPSS 1%mailvelope · mailvelopeJul 9, 2019
- CVE-2019-914717Monitor
Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page.
MediumCVSS 4.3No exploitEPSS 1%mailvelope · mailvelopeJul 9, 2019
- CVE-2019-914817Monitor
Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a va
MediumCVSS 4.3No exploitEPSS 1%mailvelope · mailvelopeJul 9, 2019