Записи 1password
12 опубликованных записей вендора 1password.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-1289 Improper Validation of Unsafe Equivalence in Input2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-427 Uncontrolled Search Path Element1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-10256Эксплойта нет | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge1password · command line interface | Критическая9,8 | — | 0,9 % | 27 окт. 2020 г. |
31Наблюдать | CVE-2020-18173Эксплойта нет | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.1password · 1password · CWE-427 | Высокая7,8 | — | 0,5 % | 26 июл. 2021 г. |
31Наблюдать | CVE-2024-42219Эксплойта нет | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is 1password · 1password · CWE-1289 | Высокая7,8 | — | 0,3 % | 6 авг. 2024 г. |
26Наблюдать | CVE-2021-26905Эксплойта нет | 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key1password · scim bridge · CWE-287 | Средняя6,5 | — | 1,0 % | 8 февр. 2021 г. |
26Наблюдать | CVE-2021-41795Эксплойта нет | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.1password · 1password | Средняя6,5 | — | 0,9 % | 29 сент. 2021 г. |
25Наблюдать | CVE-2018-13042Proof of concept | The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.1password · 1password · CWE-20 | Средняя5,9 | — | 7,9 % | 5 окт. 2018 г. |
22Наблюдать | CVE-2014-3753Эксплойта нет | AgileBits 1Password through 1.0.9.340 allows security feature bypass1password · 1password · CWE-200 | Средняя5,5 | — | 0,9 % | 9 янв. 2020 г. |
22Наблюдать | CVE-2022-29868Эксплойта нет | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.1password · 1password · CWE-312 | Средняя5,5 | — | 0,2 % | 9 мая 2022 г. |
21Наблюдать | CVE-2021-36758Эксплойта нет | 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us1password · connect · CWE-20 | Средняя5,4 | — | 0,5 % | 15 июл. 2021 г. |
19Наблюдать | CVE-2022-32550Эксплойта нет | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t1password · 1password | Средняя4,8 | — | 0,5 % | 15 июн. 2022 г. |
18Наблюдать | CVE-2024-42218Эксплойта нет | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.1password · 1password · CWE-1289 | Средняя4,7 | — | 0,2 % | 6 авг. 2024 г. |
17Наблюдать | CVE-2012-6369Эксплойта нет | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att1password · 1password · CWE-79 | Средняя4,3 | — | 1,0 % | 28 дек. 2012 г. |
- CVE-2020-1025639Наблюдать
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %1password · command line interface27 окт. 2020 г.
- CVE-2020-1817331Наблюдать
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %1password · 1password26 июл. 2021 г.
- CVE-2024-4221931Наблюдать
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %1password · 1password6 авг. 2024 г.
- CVE-2021-2690526Наблюдать
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key
СредняяCVSS 6,5Эксплойта нетEPSS 1 %1password · scim bridge8 февр. 2021 г.
- CVE-2021-4179526Наблюдать
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %1password · 1password29 сент. 2021 г.
- CVE-2018-1304225Наблюдать
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.
СредняяCVSS 5,9Proof of conceptEPSS 8 %1password · 1password5 окт. 2018 г.
- CVE-2014-375322Наблюдать
AgileBits 1Password through 1.0.9.340 allows security feature bypass
СредняяCVSS 5,5Эксплойта нетEPSS 1 %1password · 1password9 янв. 2020 г.
- CVE-2022-2986822Наблюдать
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %1password · 1password9 мая 2022 г.
- CVE-2021-3675821Наблюдать
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us
СредняяCVSS 5,4Эксплойта нетEPSS 0 %1password · connect15 июл. 2021 г.
- CVE-2022-3255019Наблюдать
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t
СредняяCVSS 4,8Эксплойта нетEPSS 1 %1password · 1password15 июн. 2022 г.
- CVE-2024-4221818Наблюдать
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
СредняяCVSS 4,7Эксплойта нетEPSS 0 %1password · 1password6 авг. 2024 г.
- CVE-2012-636917Наблюдать
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att
СредняяCVSS 4,3Эксплойта нетEPSS 1 %1password · 1password28 дек. 2012 г.