Записи Twitter
9 опубликованных записей вендора twitter.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 33,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-295 Improper Certificate Validation2
- CWE-310 Cryptographic Issues1
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
- CWE-360 Trust of System Event Data1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-95 Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2020-35774Proof of concept | server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS twitter · twitter-server · CWE-79 | Средняя5,4 | — | 85,6 % | 29 дек. 2020 г. |
30Наблюдать | CVE-2023-29218Эксплойта нет | The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrangtwitter · recommendation algorithm | Высокая7,5 | — | 1,1 % | 3 апр. 2023 г. |
29Наблюдать | CVE-2019-16263Эксплойта нет | The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.twitter · twitter kit · CWE-295 | Высокая7,4 | — | 1,0 % | 7 окт. 2019 г. |
24Наблюдать | CVE-2020-5217Эксплойта нет | Directive injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-95 | Средняя5,8 | — | 1,8 % | 22 янв. 2020 г. |
23Наблюдать | CVE-2020-5216Эксплойта нет | Limited header injection when using dynamic overrides with user input in RubyGems secure_headerstwitter · secure headers · CWE-113 | Средняя5,8 | — | 1,1 % | 22 янв. 2020 г. |
23Наблюдать | CVE-2016-10511Эксплойта нет | The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configurationtwitter · twitter · CWE-295 | Средняя5,9 | — | 0,8 % | 18 сент. 2017 г. |
21Наблюдать | CVE-2017-0911Эксплойта нет | Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attwitter · twitter kit · CWE-360 | Средняя5,4 | — | 0,5 % | 9 февр. 2018 г. |
21Наблюдать | CVE-2019-5431Эксплойта нет | This vulnerability was caused by an incomplete fix to CVE-2017-0911.twitter · twitter kit · CWE-352 | Средняя5,4 | — | 0,4 % | 6 мая 2019 г. |
21Наблюдать | CVE-2014-6838Эксплойта нет | The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, whtwitter · groupama toujours la · CWE-310 | Средняя5,4 | — | 0,3 % | 30 сент. 2014 г. |
- CVE-2020-3577447В плане
server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS
СредняяCVSS 5,4Proof of conceptEPSS 86 %twitter · twitter-server29 дек. 2020 г.
- CVE-2023-2921830Наблюдать
The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arrang
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %twitter · recommendation algorithm3 апр. 2023 г.
- CVE-2019-1626329Наблюдать
The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate.
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %twitter · twitter kit7 окт. 2019 г.
- CVE-2020-521724Наблюдать
Directive injection when using dynamic overrides with user input in RubyGems secure_headers
СредняяCVSS 5,8Эксплойта нетEPSS 2 %twitter · secure headers22 янв. 2020 г.
- CVE-2020-521623Наблюдать
Limited header injection when using dynamic overrides with user input in RubyGems secure_headers
СредняяCVSS 5,8Эксплойта нетEPSS 1 %twitter · secure headers22 янв. 2020 г.
- CVE-2016-1051123Наблюдать
The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration
СредняяCVSS 5,9Эксплойта нетEPSS 1 %twitter · twitter18 сент. 2017 г.
- CVE-2017-091121Наблюдать
Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an at
СредняяCVSS 5,4Эксплойта нетEPSS 1 %twitter · twitter kit9 февр. 2018 г.
- CVE-2019-543121Наблюдать
This vulnerability was caused by an incomplete fix to CVE-2017-0911.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %twitter · twitter kit6 мая 2019 г.
- CVE-2014-683821Наблюдать
The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, wh
СредняяCVSS 5,4Эксплойта нетEPSS 0 %twitter · groupama toujours la30 сент. 2014 г.