squareup records
12 published records for vendor squareup.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-295 Improper Certificate Validation2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2015-8969No exploit | git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.squareup · git-fastclone · CWE-77 | Critical9.8 | — | 4.8% | Nov 3, 2016 |
39Monitor | CVE-2020-36645No exploit | square squalor sql injectionsquareup · squalor · CWE-89 | Critical9.8 | — | 0.7% | Jan 7, 2023 |
37Monitor | CVE-2015-8968No exploit | git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.squareup · git-fastclone · CWE-77 | High8.8 | — | 5.2% | Nov 3, 2016 |
37Monitor | CVE-2018-1000844Proof of concept | Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabilsquareup · retrofit · CWE-611 | Critical9.1 | — | 2.2% | Dec 20, 2018 |
31Monitor | CVE-2018-1000850Proof of concept | Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder csquareup · retrofit · CWE-22 | High7.5 | — | 4.0% | Dec 20, 2018 |
30Monitor | CVE-2023-3635Proof of concept | Okio GzipSource unhandled exception Denial of Servicesquareup · okio · CWE-195 | High7.5 | — | 1.3% | Jul 12, 2023 |
30Monitor | CVE-2026-45799No exploit | Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding servicesquareup · wire · CWE-129 | High7.5 | — | 0.7% | Jul 17, 2026 |
24Monitor | CVE-2018-20200No exploit | CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext squareup · okhttp · CWE-295 | Medium5.9 | — | 2.5% | Apr 18, 2019 |
24Monitor | CVE-2016-2402Proof of concept | OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain witsquareup · okhttp · CWE-295 | Medium5.9 | — | 2.2% | Jan 30, 2017 |
23Monitor | CVE-2023-3782No exploit | DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb squareup · okhttp-brotli · CWE-400 | Medium5.9 | — | 0.7% | Jul 19, 2023 |
22Monitor | CVE-2023-0833No exploit | Red hat a-mq streams: component version with information disclosure flawsquareup · okhttp · CWE-209 | Medium5.5 | — | 0.4% | Sep 27, 2023 |
13Monitor | CVE-2021-23331No exploit | Insecure Temporary Filesquareup · connect java software development kit | Low3.3 | — | 0.3% | Feb 3, 2021 |
- CVE-2015-896940Plan
git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command.
CriticalCVSS 9.8No exploitEPSS 5%squareup · git-fastcloneNov 3, 2016
- CVE-2020-3664539Monitor
square squalor sql injection
CriticalCVSS 9.8No exploitEPSS 1%squareup · squalorJan 7, 2023
- CVE-2015-896837Monitor
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules.
HighCVSS 8.8No exploitEPSS 5%squareup · git-fastcloneNov 3, 2016
- CVE-2018-100084437Monitor
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerabil
CriticalCVSS 9.1Proof of conceptEPSS 2%squareup · retrofitDec 20, 2018
- CVE-2018-100085031Monitor
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder c
HighCVSS 7.5Proof of conceptEPSS 4%squareup · retrofitDec 20, 2018
- CVE-2023-363530Monitor
Okio GzipSource unhandled exception Denial of Service
HighCVSS 7.5Proof of conceptEPSS 1%squareup · okioJul 12, 2023
- CVE-2026-4579930Monitor
Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service
HighCVSS 7.5No exploitEPSS 1%squareup · wireJul 17, 2026
- CVE-2018-2020024Monitor
CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext
MediumCVSS 5.9No exploitEPSS 2%squareup · okhttpApr 18, 2019
- CVE-2016-240224Monitor
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain wit
MediumCVSS 5.9Proof of conceptEPSS 2%squareup · okhttpJan 30, 2017
- CVE-2023-378223Monitor
DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb
MediumCVSS 5.9No exploitEPSS 1%squareup · okhttp-brotliJul 19, 2023
- CVE-2023-083322Monitor
Red hat a-mq streams: component version with information disclosure flaw
MediumCVSS 5.5No exploitEPSS 0%squareup · okhttpSep 27, 2023
- CVE-2021-2333113Monitor
Insecure Temporary File
LowCVSS 3.3No exploitEPSS 0%squareup · connect java software development kitFeb 3, 2021