Twitter records
9 published records for vendor twitter.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-295 Improper Certificate Validation2
- CWE-310 Cryptographic Issues1
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
- CWE-360 Trust of System Event Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2020-35774Proof of concept | server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS twitter · twitter-server · CWE-79 | Medium5.4 | — | 85.6% | Dec 29, 2020 |
30Monitor | CVE-2023-29218No exploit | The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrangtwitter · recommendation algorithm | High7.5 | — | 1.1% | Apr 3, 2023 |
29Monitor | CVE-2019-16263No exploit | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.twitter · twitter kit · CWE-295 | High7.4 | — | 1.0% | Oct 7, 2019 |
24Monitor | CVE-2020-5217No exploit | Directive injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-95 | Medium5.8 | — | 1.8% | Jan 22, 2020 |
23Monitor | CVE-2020-5216No exploit | Limited header injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-113 | Medium5.8 | — | 1.1% | Jan 22, 2020 |
23Monitor | CVE-2016-10511No exploit | The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configurationtwitter · twitter · CWE-295 | Medium5.9 | — | 0.8% | Sep 18, 2017 |
21Monitor | CVE-2017-0911No exploit | Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attwitter · twitter kit · CWE-360 | Medium5.4 | — | 0.5% | Feb 9, 2018 |
21Monitor | CVE-2019-5431No exploit | This vulnerability was caused by an incomplete fix to CVE-2017-0911.twitter · twitter kit · CWE-352 | Medium5.4 | — | 0.4% | May 6, 2019 |
21Monitor | CVE-2014-6838No exploit | The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, whtwitter · groupama toujours la · CWE-310 | Medium5.4 | — | 0.3% | Sep 30, 2014 |
- CVE-2020-3577447Plan
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS
MediumCVSS 5.4Proof of conceptEPSS 86%twitter · twitter-serverDec 29, 2020
- CVE-2023-2921830Monitor
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrang
HighCVSS 7.5No exploitEPSS 1%twitter · recommendation algorithmApr 3, 2023
- CVE-2019-1626329Monitor
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.
HighCVSS 7.4No exploitEPSS 1%twitter · twitter kitOct 7, 2019
- CVE-2020-521724Monitor
Directive injection when using dynamic overrides with user input in RubyGems secure_headers
MediumCVSS 5.8No exploitEPSS 2%twitter · secure headersJan 22, 2020
- CVE-2020-521623Monitor
Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
MediumCVSS 5.8No exploitEPSS 1%twitter · secure headersJan 22, 2020
- CVE-2016-1051123Monitor
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration
MediumCVSS 5.9No exploitEPSS 1%twitter · twitterSep 18, 2017
- CVE-2017-091121Monitor
Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an at
MediumCVSS 5.4No exploitEPSS 1%twitter · twitter kitFeb 9, 2018
- CVE-2019-543121Monitor
This vulnerability was caused by an incomplete fix to CVE-2017-0911.
MediumCVSS 5.4No exploitEPSS 0%twitter · twitter kitMay 6, 2019
- CVE-2014-683821Monitor
The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, wh
MediumCVSS 5.4No exploitEPSS 0%twitter · groupama toujours laSep 30, 2014