Spotify records
3 published records for vendor spotify.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-1167No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336.spotify · spotify · CWE-78 | High8.8 | — | 4.6% | Apr 18, 2018 |
35Monitor | CVE-2018-1000843No exploit | Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 containspotify · luigi · CWE-352 | High8.8 | — | 0.8% | Dec 20, 2018 |
30Monitor | CVE-2024-42011No exploit | The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.CWE-120 | High7.5 | — | 0.6% | Oct 28, 2024 |
- CVE-2018-116736Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336.
HighCVSS 8.8No exploitEPSS 5%spotify · spotifyApr 18, 2018
- CVE-2018-100084335Monitor
Luigi version prior to version 2.8.0; after commit 53b52e12745075a8acc016d33945d9d6a7a6aaeb; after GitHub PR spotify/luigi/pull/1870 contain
HighCVSS 8.8No exploitEPSS 1%spotify · luigiDec 20, 2018
- CVE-2024-4201130Monitor
The Spotify app 8.9.58 for iOS has a buffer overflow in its use of strcat.
HighCVSS 7.5No exploitEPSS 1%Oct 28, 2024