Записи telegram
37 опубликованных записей вендора telegram.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 21,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-863 Incorrect Authorization2
- CWE-312 Cleartext Storage of Sensitive Information2
- CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')2
- CWE-287 Improper Authentication2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2018-17613Эксплойта нет | Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCKtelegram · telegram desktop · CWE-522 | Критическая9,8 | — | 1,6 % | 28 сент. 2018 г. |
39Наблюдать | CVE-2021-40532Эксплойта нет | Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.telegram · web k alpha | Критическая9,8 | — | 1,3 % | 6 сент. 2021 г. |
36Наблюдать | CVE-2019-10044Эксплойта нет | Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attatelegram · telegram | Высокая8,8 | — | 3,3 % | 25 мар. 2019 г. |
36Наблюдать | CVE-2017-17715Эксплойта нет | The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal vtelegram · telegram messenger · CWE-22 | Высокая8,8 | — | 1,7 % | 16 дек. 2017 г. |
32Наблюдать | CVE-2020-17448Эксплойта нет | Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstratedtelegram · telegram desktop · CWE-863 | Высокая7,8 | — | 2,3 % | 11 авг. 2020 г. |
32Наблюдать | CVE-2018-20436Эксплойта нет | The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed whiltelegram · telegram · CWE-918 | Высокая8,1 | — | 1,6 % | 24 дек. 2018 г. |
30Наблюдать | CVE-2018-17231Эксплойта нет | Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Etelegram · telegram desktop · CWE-617 | Высокая7,5 | — | 1,5 % | 19 сент. 2018 г. |
30Наблюдать | CVE-2014-8688Эксплойта нет | An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android.telegram · messenger · CWE-200 | Высокая7,5 | — | 1,3 % | 14 мар. 2017 г. |
28Наблюдать | CVE-2024-7014Proof of concept | Improper multimedia file attachment validation in Telegram for Android apptelegram · telegram · CWE-20 | Высокая7,1 | — | 1,4 % | 23 июл. 2024 г. |
28Наблюдать | CVE-2021-31320Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::gentelegram · telegram · CWE-787 | Высокая7,1 | — | 1,2 % | 18 мая 2021 г. |
28Наблюдать | CVE-2021-31321Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic futelegram · telegram · CWE-787 | Высокая7,1 | — | 1,1 % | 18 мая 2021 г. |
27Наблюдать | CVE-2020-12474Эксплойта нет | Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Puntelegram · telegram | Средняя6,5 | — | 2,6 % | 1 мая 2020 г. |
27Наблюдать | CVE-2018-17780Эксплойта нет | Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call telegram · telegram desktop · CWE-200 | Средняя6,5 | — | 1,8 % | 29 сент. 2018 г. |
27Наблюдать | CVE-2018-15543Эксплойта нет | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.telegram · telegram · CWE-287 | Средняя6,8 | — | 0,4 % | 9 окт. 2018 г. |
25Наблюдать | CVE-2018-15542Эксплойта нет | An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.telegram · telegram · CWE-287 | Средняя6,4 | — | 0,3 % | 9 окт. 2018 г. |
24Наблюдать | CVE-2021-37596Эксплойта нет | Telegram Web K Alpha 0.6.1 allows XSS via a document name.telegram · web k alpha · CWE-79 | Средняя6,1 | — | 0,6 % | 30 июл. 2021 г. |
24Наблюдать | CVE-2022-43363Эксплойта нет | Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website.telegram · telegram · CWE-79 | Средняя6,1 | — | 0,4 % | 6 дек. 2022 г. |
24Наблюдать | CVE-2020-10570Эксплойта нет | The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intendedtelegram · telegram | Средняя6,1 | — | 0,4 % | 24 мар. 2020 г. |
22Наблюдать | CVE-2019-15514Proof of concept | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Notelegram · telegram | Средняя5,3 | — | 2,3 % | 23 авг. 2019 г. |
22Наблюдать | CVE-2021-31322Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populatelegram · telegram · CWE-787 | Средняя5,5 | — | 1,4 % | 18 мая 2021 г. |
22Наблюдать | CVE-2021-31319Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate telegram · telegram · CWE-190 | Средняя5,5 | — | 1,3 % | 18 мая 2021 г. |
22Наблюдать | CVE-2021-31315Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of thtelegram · telegram · CWE-787 | Средняя5,5 | — | 1,3 % | 18 мая 2021 г. |
22Наблюдать | CVE-2021-31317Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of thtelegram · telegram · CWE-843 | Средняя5,5 | — | 1,3 % | 18 мая 2021 г. |
22Наблюдать | CVE-2021-31318Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTComptelegram · telegram · CWE-843 | Средняя5,5 | — | 1,3 % | 18 мая 2021 г. |
22Наблюдать | CVE-2021-31323Эксплойта нет | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::ptelegram · telegram · CWE-787 | Средняя5,5 | — | 1,3 % | 18 мая 2021 г. |
- CVE-2018-1761339Наблюдать
Telegram Desktop (aka tdesktop) 1.3.16 alpha, when "Use proxy" is enabled, sends credentials and application data in cleartext over the SOCK
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %telegram · telegram desktop28 сент. 2018 г.
- CVE-2021-4053239Наблюдать
Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %telegram · web k alpha6 сент. 2021 г.
- CVE-2019-1004436Наблюдать
Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph atta
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %telegram · telegram25 мар. 2019 г.
- CVE-2017-1771536Наблюдать
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal v
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %telegram · telegram messenger16 дек. 2017 г.
- CVE-2020-1744832Наблюдать
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %telegram · telegram desktop11 авг. 2020 г.
- CVE-2018-2043632Наблюдать
The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed whil
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %telegram · telegram24 дек. 2018 г.
- CVE-2018-1723130Наблюдать
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "E
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %telegram · telegram desktop19 сент. 2018 г.
- CVE-2014-868830Наблюдать
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %telegram · messenger14 мар. 2017 г.
- CVE-2024-701428Наблюдать
Improper multimedia file attachment validation in Telegram for Android app
ВысокаяCVSS 7,1Proof of conceptEPSS 1 %telegram · telegram23 июл. 2024 г.
- CVE-2021-3132028Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::gen
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3132128Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic fu
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2020-1247427Наблюдать
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Pun
СредняяCVSS 6,5Эксплойта нетEPSS 3 %telegram · telegram1 мая 2020 г.
- CVE-2018-1778027Наблюдать
Telegram Desktop (aka tdesktop) 1.3.14, and Telegram 3.3.0.0 WP8.1 on Windows, leaks end-user public and private IP addresses during a call
СредняяCVSS 6,5Эксплойта нетEPSS 2 %telegram · telegram desktop29 сент. 2018 г.
- CVE-2018-1554327Наблюдать
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %telegram · telegram9 окт. 2018 г.
- CVE-2018-1554225Наблюдать
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android.
СредняяCVSS 6,4Эксплойта нетEPSS 0 %telegram · telegram9 окт. 2018 г.
- CVE-2021-3759624Наблюдать
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %telegram · web k alpha30 июл. 2021 г.
- CVE-2022-4336324Наблюдать
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %telegram · telegram6 дек. 2022 г.
- CVE-2020-1057024Наблюдать
The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended
СредняяCVSS 6,1Эксплойта нетEPSS 0 %telegram · telegram24 мар. 2020 г.
- CVE-2019-1551422Наблюдать
The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is No
СредняяCVSS 5,3Proof of conceptEPSS 2 %telegram · telegram23 авг. 2019 г.
- CVE-2021-3132222Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::popula
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3131922Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3131522Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of th
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3131722Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of th
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3131822Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTComp
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.
- CVE-2021-3132322Наблюдать
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::p
СредняяCVSS 5,5Эксплойта нетEPSS 1 %telegram · telegram18 мая 2021 г.