Skip to content
Noroxi

mailvelope records

4 published records for vendor mailvelope.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19

Bar: total · dark part: CISA KEV.

All records

4 records
  • CVE-2019-9149
    26Monitor

    Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API.

    MediumCVSS 6.5No exploitEPSS 1%

    mailvelope · mailvelopeJul 9, 2019

  • CVE-2019-9150
    21Monitor

    Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page.

    MediumCVSS 5.3No exploitEPSS 1%

    mailvelope · mailvelopeJul 9, 2019

  • CVE-2019-9147
    17Monitor

    Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page.

    MediumCVSS 4.3No exploitEPSS 1%

    mailvelope · mailvelopeJul 9, 2019

  • CVE-2019-9148
    17Monitor

    Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain users without a va

    MediumCVSS 4.3No exploitEPSS 1%

    mailvelope · mailvelopeJul 9, 2019