Skip to content
Noroxi

squareup records

12 published records for vendor squareup.

All records

12 records
  • git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.

    CriticalCVSS 9.8No exploitEPSS 5%

    squareup · git-fastcloneNov 3, 2016

  • square squalor sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    squareup · squalorJan 7, 2023

  • CVE-2015-8968
    37Monitor

    git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.

    HighCVSS 8.8No exploitEPSS 5%

    squareup · git-fastcloneNov 3, 2016

  • Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabil

    CriticalCVSS 9.1Proof of conceptEPSS 2%

    squareup · retrofitDec 20, 2018

  • Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder c

    HighCVSS 7.5Proof of conceptEPSS 4%

    squareup · retrofitDec 20, 2018

  • CVE-2023-3635
    30Monitor

    Okio GzipSource unhandled exception Denial of Service

    HighCVSS 7.5Proof of conceptEPSS 1%

    squareup · okioJul 12, 2023

  • Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service

    HighCVSS 7.5No exploitEPSS 1%

    squareup · wireJul 17, 2026

  • CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext

    MediumCVSS 5.9No exploitEPSS 2%

    squareup · okhttpApr 18, 2019

  • CVE-2016-2402
    24Monitor

    OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain wit

    MediumCVSS 5.9Proof of conceptEPSS 2%

    squareup · okhttpJan 30, 2017

  • CVE-2023-3782
    23Monitor

    DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb

    MediumCVSS 5.9No exploitEPSS 1%

    squareup · okhttp-brotliJul 19, 2023

  • CVE-2023-0833
    22Monitor

    Red hat a-mq streams: component version with information disclosure flaw

    MediumCVSS 5.5No exploitEPSS 0%

    squareup · okhttpSep 27, 2023

  • Insecure Temporary File

    LowCVSS 3.3No exploitEPSS 0%

    squareup · connect java software development kitFeb 3, 2021