Записи Matrix
82 опубликованных записей вендора matrix.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 91,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation14
- CWE-287 Improper Authentication10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-770 Allocation of Resources Without Limits or Throttling4
- CWE-400 Uncontrolled Resource Consumption4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
82 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-34813Эксплойта нет | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room matrix · olm · CWE-787 | Критическая9,8 | — | 4,3 % | 16 июн. 2021 г. |
40В плане | CVE-2021-44538Эксплойта нет | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.matrix · element · CWE-119 | Критическая9,8 | — | 1,9 % | 14 дек. 2021 г. |
39Наблюдать | CVE-2019-18835Эксплойта нет | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.matrix · synapse · CWE-345 | Критическая9,8 | — | 0,9 % | 7 нояб. 2019 г. |
39Наблюдать | CVE-2023-38690Эксплойта нет | matrix-appservice-irc IRC command injection via admin commands containing newlinesmatrix · matrix irc bridge · CWE-20 | Критическая9,8 | — | 0,9 % | 4 авг. 2023 г. |
36Наблюдать | CVE-2023-43656Эксплойта нет | Sandbox escape for instances that have enabled transformation functions in matrix-hookshotmatrix · hookshot · CWE-74 | Критическая9,0 | — | 0,3 % | 27 сент. 2023 г. |
35Наблюдать | CVE-2018-16515Эксплойта нет | Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper trmatrix · synapse · CWE-347 | Высокая8,8 | — | 1,5 % | 18 сент. 2018 г. |
35Наблюдать | CVE-2022-29166Эксплойта нет | Improper handling of multiline messages in matrix-appservice-ircmatrix · matrix irc bridge · CWE-74 | Высокая8,8 | — | 1,0 % | 5 мая 2022 г. |
35Наблюдать | CVE-2022-39203Эксплойта нет | Parsing issue in matrix-org/node-irc leading to room takeoversmatrix · matrix irc bridge · CWE-269 | Высокая8,8 | — | 0,8 % | 13 сент. 2022 г. |
35Наблюдать | CVE-2022-36009Эксплойта нет | Incorrect parsing of access level in gomatrixserverlib and dendritematrix · dendrite · CWE-863 | Высокая8,8 | — | 0,8 % | 19 авг. 2022 г. |
34Наблюдать | CVE-2024-52815Эксплойта нет | Synapse allows a a malformed invite to break the invitee's `/sync`matrix · synapse · CWE-20 | Высокая8,7 | — | 0,6 % | 3 дек. 2024 г. |
32Наблюдать | CVE-2021-21332Эксплойта нет | Cross-site scripting (XSS) vulnerability in the password reset endpointmatrix · synapse · CWE-79 | Высокая8,2 | — | 1,2 % | 26 мар. 2021 г. |
32Наблюдать | CVE-2023-28427Эксплойта нет | Prototype pollution in matrix-js-sdkmatrix · javascript sdk · CWE-1321 | Высокая8,2 | — | 1,2 % | 28 мар. 2023 г. |
32Наблюдать | CVE-2024-52805Эксплойта нет | Synapse allows unsupported content types to lead to memory exhaustionmatrix · synapse · CWE-770 | Высокая8,2 | — | 0,7 % | 3 дек. 2024 г. |
32Наблюдать | CVE-2024-53863Эксплойта нет | Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decodersmatrix · synapse · CWE-434 | Высокая8,2 | — | 0,6 % | 3 дек. 2024 г. |
31Наблюдать | CVE-2020-26890Эксплойта нет | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, almatrix · synapse · CWE-20 | Высокая7,5 | — | 3,0 % | 23 нояб. 2020 г. |
31Наблюдать | CVE-2019-5885Эксплойта нет | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secrematrix · synapse · CWE-330 | Высокая7,5 | — | 2,4 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2018-12423Эксплойта нет | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.matrix · synapse | Высокая7,5 | — | 1,8 % | 14 июн. 2018 г. |
31Наблюдать | CVE-2021-29430Эксплойта нет | Denial of service attack via memory exhaustionmatrix · sydent · CWE-20 | Высокая7,5 | — | 1,8 % | 15 апр. 2021 г. |
31Наблюдать | CVE-2018-12291Эксплойта нет | The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events fematrix · synapse | Высокая7,5 | — | 1,8 % | 13 июн. 2018 г. |
31Наблюдать | CVE-2019-11842Эксплойта нет | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1.matrix · sydent · CWE-338 | Высокая7,5 | — | 1,8 % | 9 мая 2019 г. |
30Наблюдать | CVE-2021-41281Эксплойта нет | Path traversal in Matrix Synapsematrix · synapse · CWE-22 | Высокая7,5 | — | 1,6 % | 23 нояб. 2021 г. |
30Наблюдать | CVE-2018-10657Эксплойта нет | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusablmatrix · synapse · CWE-20 | Высокая7,5 | — | 1,5 % | 2 мая 2018 г. |
30Наблюдать | CVE-2022-39249Эксплойта нет | Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsmatrix · javascript sdk · CWE-287 | Высокая7,5 | — | 1,3 % | 28 сент. 2022 г. |
30Наблюдать | CVE-2025-30355Эксплойта нет | Synapse vulnerable to federation denial of service via malformed eventsmatrix · synapse · CWE-20 | Высокая7,5 | — | 1,2 % | 26 мар. 2025 г. |
30Наблюдать | CVE-2022-39250Эксплойта нет | Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationmatrix · javascript sdk · CWE-287 | Высокая7,5 | — | 1,2 % | 29 сент. 2022 г. |
- CVE-2021-3481340В плане
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %matrix · olm16 июн. 2021 г.
- CVE-2021-4453840В плане
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matrix · element14 дек. 2021 г.
- CVE-2019-1883539Наблюдать
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %matrix · synapse7 нояб. 2019 г.
- CVE-2023-3869039Наблюдать
matrix-appservice-irc IRC command injection via admin commands containing newlines
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %matrix · matrix irc bridge4 авг. 2023 г.
- CVE-2023-4365636Наблюдать
Sandbox escape for instances that have enabled transformation functions in matrix-hookshot
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %matrix · hookshot27 сент. 2023 г.
- CVE-2018-1651535Наблюдать
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper tr
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %matrix · synapse18 сент. 2018 г.
- CVE-2022-2916635Наблюдать
Improper handling of multiline messages in matrix-appservice-irc
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %matrix · matrix irc bridge5 мая 2022 г.
- CVE-2022-3920335Наблюдать
Parsing issue in matrix-org/node-irc leading to room takeovers
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %matrix · matrix irc bridge13 сент. 2022 г.
- CVE-2022-3600935Наблюдать
Incorrect parsing of access level in gomatrixserverlib and dendrite
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %matrix · dendrite19 авг. 2022 г.
- CVE-2024-5281534Наблюдать
Synapse allows a a malformed invite to break the invitee's `/sync`
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %matrix · synapse3 дек. 2024 г.
- CVE-2021-2133232Наблюдать
Cross-site scripting (XSS) vulnerability in the password reset endpoint
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %matrix · synapse26 мар. 2021 г.
- CVE-2023-2842732Наблюдать
Prototype pollution in matrix-js-sdk
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %matrix · javascript sdk28 мар. 2023 г.
- CVE-2024-5280532Наблюдать
Synapse allows unsupported content types to lead to memory exhaustion
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %matrix · synapse3 дек. 2024 г.
- CVE-2024-5386332Наблюдать
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %matrix · synapse3 дек. 2024 г.
- CVE-2020-2689031Наблюдать
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, al
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %matrix · synapse23 нояб. 2020 г.
- CVE-2019-588531Наблюдать
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secre
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · synapse21 мар. 2019 г.
- CVE-2018-1242331Наблюдать
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · synapse14 июн. 2018 г.
- CVE-2021-2943031Наблюдать
Denial of service attack via memory exhaustion
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · sydent15 апр. 2021 г.
- CVE-2018-1229131Наблюдать
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events fe
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · synapse13 июн. 2018 г.
- CVE-2019-1184231Наблюдать
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · sydent9 мая 2019 г.
- CVE-2021-4128130Наблюдать
Path traversal in Matrix Synapse
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · synapse23 нояб. 2021 г.
- CVE-2018-1065730Наблюдать
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusabl
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrix · synapse2 мая 2018 г.
- CVE-2022-3924930Наблюдать
Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %matrix · javascript sdk28 сент. 2022 г.
- CVE-2025-3035530Наблюдать
Synapse vulnerable to federation denial of service via malformed events
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %matrix · synapse26 мар. 2025 г.
- CVE-2022-3925030Наблюдать
Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %matrix · javascript sdk29 сент. 2022 г.