Записи linecorp
93 опубликованных записей вендора linecorp.
Профиль для исследователя
- Попали в KEV
- 1 · 1,1 %
- С эксплойтом
- 1 · 1,1 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 7,5 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor20
- CWE-326 Inadequate Encryption Strength10
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-451 User Interface (UI) Misrepresentation of Critical Information5
- CWE-269 Improper Privilege Management4
- CWE-295 Improper Certificate Validation4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
93 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
39Наблюдать | CVE-2023-5554Эксплойта нет | Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.linecorp · line · CWE-295 | Критическая9,8 | — | 0,2 % | 12 окт. 2023 г. |
36Наблюдать | CVE-2019-6007Эксплойта нет | Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arlinecorp · apng-drawable · CWE-190 | Высокая8,8 | — | 2,0 % | 12 сент. 2019 г. |
36Наблюдать | CVE-2024-1735Эксплойта нет | A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentlinecorp · armeria · CWE-287 | Критическая9,1 | — | 0,8 % | 26 февр. 2024 г. |
35Наблюдать | CVE-2021-38388Эксплойта нет | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the linecorp · central dogma · CWE-862 | Высокая8,8 | — | 0,9 % | 8 сент. 2021 г. |
33Наблюдать | CVE-2016-4850Эксплойта нет | LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.linecorp · line · CWE-284 | Высокая8,1 | — | 2,2 % | 20 апр. 2017 г. |
32Наблюдать | CVE-2019-6010Эксплойта нет | Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of servicelinecorp · line · CWE-190 | Высокая7,8 | — | 1,7 % | 19 сент. 2019 г. |
32Наблюдать | CVE-2023-39739Эксплойта нет | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted brlinecorp · regina sweets\&bakery · CWE-200 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-39735Эксплойта нет | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadlinecorp · uomasa saiji new · CWE-200 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-39736Эксплойта нет | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted brlinecorp · fukunaga memberscard · CWE-200 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-39737Эксплойта нет | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messalinecorp · matsuya · CWE-200 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-39734Эксплойта нет | The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token anlinecorp · trackdiner10\/10 mc · CWE-269 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-43301Эксплойта нет | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel aclinecorp · line · CWE-94 | Высокая8,2 | — | 0,6 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-43302Эксплойта нет | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access tokenlinecorp · line | Высокая8,2 | — | 0,6 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-39740Эксплойта нет | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadlinecorp · onigiriya-musubee · CWE-269 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-39732Эксплойта нет | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broalinecorp · tokueimaru waiting · CWE-269 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-43305Эксплойта нет | An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access linecorp · line | Высокая8,2 | — | 0,6 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-39733Эксплойта нет | The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast mlinecorp · tonton-tei · CWE-269 | Высокая8,2 | — | 0,6 % | 25 окт. 2023 г. |
32Наблюдать | CVE-2023-43304Эксплойта нет | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access linecorp · line · CWE-290 | Высокая8,2 | — | 0,5 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-43300Эксплойта нет | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acceslinecorp · line | Высокая8,2 | — | 0,5 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-43303Эксплойта нет | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channelinecorp · line | Высокая8,2 | — | 0,5 % | 7 дек. 2023 г. |
32Наблюдать | CVE-2023-45559Эксплойта нет | An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.linecorp · line | Высокая8,2 | — | 0,5 % | 3 янв. 2024 г. |
31Наблюдать | CVE-2021-43795Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in com.linecorp.armeria:armerialinecorp · armeria · CWE-22 | Высокая7,5 | — | 1,7 % | 2 дек. 2021 г. |
31Наблюдать | CVE-2018-0609Эксплойта нет | Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL ilinecorp · line · CWE-426 | Высокая7,8 | — | 0,8 % | 26 июн. 2018 г. |
31Наблюдать | CVE-2022-29505Эксплойта нет | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilegelinecorp · line | Высокая7,8 | — | 0,5 % | 27 апр. 2022 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2023-555439Наблюдать
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %linecorp · line12 окт. 2023 г.
- CVE-2019-600736Наблюдать
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute ar
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %linecorp · apng-drawable12 сент. 2019 г.
- CVE-2024-173536Наблюдать
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authent
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %linecorp · armeria26 февр. 2024 г.
- CVE-2021-3838835Наблюдать
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %linecorp · central dogma8 сент. 2021 г.
- CVE-2016-485033Наблюдать
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %linecorp · line20 апр. 2017 г.
- CVE-2019-601032Наблюдать
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %linecorp · line19 сент. 2019 г.
- CVE-2023-3973932Наблюдать
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted br
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · regina sweets\&bakery25 окт. 2023 г.
- CVE-2023-3973532Наблюдать
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broad
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · uomasa saiji new25 окт. 2023 г.
- CVE-2023-3973632Наблюдать
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted br
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · fukunaga memberscard25 окт. 2023 г.
- CVE-2023-3973732Наблюдать
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messa
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · matsuya25 окт. 2023 г.
- CVE-2023-3973432Наблюдать
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token an
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · trackdiner10\/10 mc25 окт. 2023 г.
- CVE-2023-4330132Наблюдать
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel ac
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-4330232Наблюдать
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-3974032Наблюдать
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broad
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · onigiriya-musubee25 окт. 2023 г.
- CVE-2023-3973232Наблюдать
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broa
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · tokueimaru waiting25 окт. 2023 г.
- CVE-2023-4330532Наблюдать
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-3973332Наблюдать
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast m
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · tonton-tei25 окт. 2023 г.
- CVE-2023-4330432Наблюдать
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-4330032Наблюдать
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel acces
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-4330332Наблюдать
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channe
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %linecorp · line7 дек. 2023 г.
- CVE-2023-4555932Наблюдать
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %linecorp · line3 янв. 2024 г.
- CVE-2021-4379531Наблюдать
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in com.linecorp.armeria:armeria
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %linecorp · armeria2 дек. 2021 г.
- CVE-2018-060931Наблюдать
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL i
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %linecorp · line26 июн. 2018 г.
- CVE-2022-2950531Наблюдать
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linecorp · line27 апр. 2022 г.