Skip to content
Noroxi

Matrix records

82 published records for vendor matrix.

All records

82 records
  • Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room

    CriticalCVSS 9.8No exploitEPSS 4%

    matrix · olmJun 16, 2021

  • The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.

    CriticalCVSS 9.8No exploitEPSS 2%

    matrix · elementDec 14, 2021

  • Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.

    CriticalCVSS 9.8No exploitEPSS 1%

    matrix · synapseNov 7, 2019

  • matrix-appservice-irc IRC command injection via admin commands containing newlines

    CriticalCVSS 9.8No exploitEPSS 1%

    matrix · matrix irc bridgeAug 4, 2023

  • Sandbox escape for instances that have enabled transformation functions in matrix-hookshot

    CriticalCVSS 9.0No exploitEPSS 0%

    matrix · hookshotSep 27, 2023

  • Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper tr

    HighCVSS 8.8No exploitEPSS 2%

    matrix · synapseSep 18, 2018

  • Improper handling of multiline messages in matrix-appservice-irc

    HighCVSS 8.8No exploitEPSS 1%

    matrix · matrix irc bridgeMay 5, 2022

  • Parsing issue in matrix-org/node-irc leading to room takeovers

    HighCVSS 8.8No exploitEPSS 1%

    matrix · matrix irc bridgeSep 13, 2022

  • Incorrect parsing of access level in gomatrixserverlib and dendrite

    HighCVSS 8.8No exploitEPSS 1%

    matrix · dendriteAug 19, 2022

  • Synapse allows a a malformed invite to break the invitee's `/sync`

    HighCVSS 8.7No exploitEPSS 1%

    matrix · synapseDec 3, 2024

  • Cross-site scripting (XSS) vulnerability in the password reset endpoint

    HighCVSS 8.2No exploitEPSS 1%

    matrix · synapseMar 26, 2021

  • Prototype pollution in matrix-js-sdk

    HighCVSS 8.2No exploitEPSS 1%

    matrix · javascript sdkMar 28, 2023

  • Synapse allows unsupported content types to lead to memory exhaustion

    HighCVSS 8.2No exploitEPSS 1%

    matrix · synapseDec 3, 2024

  • Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

    HighCVSS 8.2No exploitEPSS 1%

    matrix · synapseDec 3, 2024

  • Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, al

    HighCVSS 7.5No exploitEPSS 3%

    matrix · synapseNov 23, 2020

  • CVE-2019-5885
    31Monitor

    Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secre

    HighCVSS 7.5No exploitEPSS 2%

    matrix · synapseMar 21, 2019

  • In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

    HighCVSS 7.5No exploitEPSS 2%

    matrix · synapseJun 14, 2018

  • Denial of service attack via memory exhaustion

    HighCVSS 7.5No exploitEPSS 2%

    matrix · sydentApr 15, 2021

  • The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events fe

    HighCVSS 7.5No exploitEPSS 2%

    matrix · synapseJun 13, 2018

  • An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1.

    HighCVSS 7.5No exploitEPSS 2%

    matrix · sydentMay 9, 2019

  • Path traversal in Matrix Synapse

    HighCVSS 7.5No exploitEPSS 2%

    matrix · synapseNov 23, 2021

  • Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusabl

    HighCVSS 7.5No exploitEPSS 2%

    matrix · synapseMay 2, 2018

  • Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions

    HighCVSS 7.5No exploitEPSS 1%

    matrix · javascript sdkSep 28, 2022

  • Synapse vulnerable to federation denial of service via malformed events

    HighCVSS 7.5No exploitEPSS 1%

    matrix · synapseMar 26, 2025

  • Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification

    HighCVSS 7.5No exploitEPSS 1%

    matrix · javascript sdkSep 29, 2022