Перейти к содержимому
Noroxi

CWE-939 · 22 записей

Improper Authorization in Handler for Custom URL Scheme

CVE этого класса

22 записей

  • CVE-2026-53407
    39Наблюдать

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    zoom · workplace12 июн. 2026 г.

  • CVE-2023-43582
    35Наблюдать

    Improper authorization in some Zoom clients may allow an authorized user to conduct an escalation of privilege via network access.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    zoom · meetings14 нояб. 2023 г.

  • CVE-2026-35394
    35Наблюдать

    Mobile Next has Arbitrary Android Intent Execution via mobile_open_url

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    mobilenexthq · mobile mcp6 апр. 2026 г.

  • CVE-2024-33606
    34Наблюдать

    MicroDicom DICOM Viewer Improper Authorization in Handler for Custom URL Scheme

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    microdicom · dicom viewer11 июн. 2024 г.

  • CVE-2026-6445
    34Наблюдать

    A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    everpure · flasharray9 июн. 2026 г.

  • CVE-2026-53408
    32Наблюдать

    Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allo

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    zoom · meeting software development kit12 июн. 2026 г.

  • CVE-2020-11000
    26Наблюдать

    Improper URL validation in GreenBrowser

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    greenbrowser project · greenbrowser8 апр. 2020 г.

  • CVE-2026-3471
    26Наблюдать

    Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Desktop App

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    mattermost · mattermost desktop18 мая 2026 г.

  • CVE-2026-1046
    26Наблюдать

    Arbitrary application execution via unvalidated server-controlled URLs in Help menu

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    mattermost · mattermost desktop16 февр. 2026 г.

  • CVE-2026-33335
    25Наблюдать

    Vikunja Desktop allows arbitrary local application invocation via unvalidated shell.openExternal

    СредняяCVSS 6,4Эксплойта нетEPSS 0 %

    vikunja · vikunja24 мар. 2026 г.

  • CVE-2026-26123
    22Наблюдать

    Microsoft Authenticator Information Disclosure Vulnerability

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    microsoft · authenticator10 мар. 2026 г.

  • CVE-2022-20736
    21Наблюдать

    Cisco AppDynamics Controller Authorization Bypass Vulnerability

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    cisco · appdynamics controller15 июн. 2022 г.

  • CVE-2026-21075
    21Наблюдать

    Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive inform

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    samsung mobile · my galaxy10 авг. 2026 г.

  • CVE-2025-41408
    21Наблюдать

    Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.15.0 allows a remote

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    ly corporation · "yahoo! shopping" app for android5 сент. 2025 г.

  • CVE-2026-21062
    19Наблюдать

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    samsung · android10 авг. 2026 г.

  • CVE-2026-73335
    18Наблюдать

    Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939).

    СредняяCVSS 4,6Эксплойта нетEPSS 0 %

    digital agency · android app "myna point"26 авг. 2026 г.

  • CVE-2024-45203
    17Наблюдать

    Improper authorization in handler for custom URL scheme issue in "@cosme" App for Android versions prior 5.69.0 and "@cosme" App for iOS ver

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    istyle · \@cosme9 сент. 2024 г.

  • CVE-2024-35298
    17Наблюдать

    Improper authorization in handler for custom URL scheme issue in 'ZOZOTOWN' App for Android versions prior to 7.39.6 allows an attacker to l

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    zozo, inc. · 'zozotown' app for android19 июн. 2024 г.

  • CVE-2025-5020
    17Наблюдать

    Links using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addresses

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    mozilla · firefox21 мая 2025 г.

  • CVE-2024-54014
    14Наблюдать

    Improper authorization in handler for custom URL scheme issue in 'Skylark' App for Android 6.2.13 and earlier and 'Skylark' App for iOS 6.2.

    НизкаяCVSS 3,6Эксплойта нетEPSS 0 %

    skylark holdings co., ltd. · 'skylark' app for android4 дек. 2024 г.

  • CVE-2024-54125
    13Наблюдать

    Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker t

    НизкаяCVSS 3,3Эксплойта нетEPSS 0 %

    shueisha inc. · "shonen jump+" app for android17 дек. 2024 г.

  • CVE-2025-67739
    12Наблюдать

    In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

    НизкаяCVSS 3,1Эксплойта нетEPSS 0 %

    jetbrains · teamcity11 дек. 2025 г.

Все классы уязвимостей