1password kayıtları
1password üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1289 Improper Validation of Unsafe Equivalence in Input2
- CWE-20 Improper Input Validation2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-427 Uncontrolled Search Path Element1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-10256İstismar yok | An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge1password · command line interface | Kritik9,8 | — | %0,9 | 27 Eki 2020 |
31İzleyin | CVE-2020-18173İstismar yok | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.1password · 1password · CWE-427 | Yüksek7,8 | — | %0,5 | 26 Tem 2021 |
31İzleyin | CVE-2024-42219İstismar yok | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is 1password · 1password · CWE-1289 | Yüksek7,8 | — | %0,3 | 6 Ağu 2024 |
26İzleyin | CVE-2021-26905İstismar yok | 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key1password · scim bridge · CWE-287 | Orta6,5 | — | %1,0 | 8 Şub 2021 |
26İzleyin | CVE-2021-41795İstismar yok | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.1password · 1password | Orta6,5 | — | %0,9 | 29 Eyl 2021 |
25İzleyin | CVE-2018-13042Kavram kanıtı | The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.1password · 1password · CWE-20 | Orta5,9 | — | %7,9 | 5 Eki 2018 |
22İzleyin | CVE-2014-3753İstismar yok | AgileBits 1Password through 1.0.9.340 allows security feature bypass1password · 1password · CWE-200 | Orta5,5 | — | %0,9 | 9 Oca 2020 |
22İzleyin | CVE-2022-29868İstismar yok | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.1password · 1password · CWE-312 | Orta5,5 | — | %0,2 | 9 May 2022 |
21İzleyin | CVE-2021-36758İstismar yok | 1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us1password · connect · CWE-20 | Orta5,4 | — | %0,5 | 15 Tem 2021 |
19İzleyin | CVE-2022-32550İstismar yok | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t1password · 1password | Orta4,8 | — | %0,5 | 15 Haz 2022 |
18İzleyin | CVE-2024-42218İstismar yok | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.1password · 1password · CWE-1289 | Orta4,7 | — | %0,2 | 6 Ağu 2024 |
17İzleyin | CVE-2012-6369İstismar yok | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att1password · 1password · CWE-79 | Orta4,3 | — | %1,0 | 28 Ara 2012 |
- CVE-2020-1025639İzleyin
An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge
KritikCVSS 9,8İstismar yokEPSS %11password · command line interface27 Eki 2020
- CVE-2020-1817331İzleyin
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
YüksekCVSS 7,8İstismar yokEPSS %01password · 1password26 Tem 2021
- CVE-2024-4221931İzleyin
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is
YüksekCVSS 7,8İstismar yokEPSS %01password · 1password6 Ağu 2024
- CVE-2021-2690526İzleyin
1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure of a TLS private key
OrtaCVSS 6,5İstismar yokEPSS %11password · scim bridge8 Şub 2021
- CVE-2021-4179526İzleyin
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass.
OrtaCVSS 6,5İstismar yokEPSS %11password · 1password29 Eyl 2021
- CVE-2018-1304225İzleyin
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability.
OrtaCVSS 5,9Kavram kanıtıEPSS %81password · 1password5 Eki 2018
- CVE-2014-375322İzleyin
AgileBits 1Password through 1.0.9.340 allows security feature bypass
OrtaCVSS 5,5İstismar yokEPSS %11password · 1password9 Oca 2020
- CVE-2022-2986822İzleyin
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass.
OrtaCVSS 5,5İstismar yokEPSS %01password · 1password9 May 2022
- CVE-2021-3675821İzleyin
1Password Connect server before 1.2 is missing validation checks, permitting users to create Secrets Automation access tokens that can be us
OrtaCVSS 5,4İstismar yokEPSS %01password · connect15 Tem 2021
- CVE-2022-3255019İzleyin
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to t
OrtaCVSS 4,8İstismar yokEPSS %11password · 1password15 Haz 2022
- CVE-2024-4221818İzleyin
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
OrtaCVSS 4,7İstismar yokEPSS %01password · 1password6 Ağu 2024
- CVE-2012-636917İzleyin
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote att
OrtaCVSS 4,3İstismar yokEPSS %11password · 1password28 Ara 2012