İçeriğe atla
Noroxi

dropbox kayıtları

dropbox üreticisine ait 16 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
1
Düzeltme kaydı olan
%12,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

16 kayıt
  • CVE-2022-4768
    39İzleyin

    Dropbox merou SSH Public Key public_key.py add_public_key injection

    KritikCVSS 9,8İstismar yokEPSS %1

    dropbox · merou27 Ara 2022

  • CVE-2024-25718
    39İzleyin

    In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access

    KritikCVSS 9,8İstismar yokEPSS %1

    dropbox · samly11 Şub 2024

  • CVE-2024-5924
    35İzleyin

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %1

    dropbox · dropbox desktop13 Haz 2024

  • CVE-2018-20819
    31İzleyin

    io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffe

    YüksekCVSS 7,8İstismar yokEPSS %1

    dropbox · lepton23 Nis 2019

  • CVE-2019-12171
    31İzleyin

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memo

    YüksekCVSS 7,8İstismar yokEPSS %1

    dropbox · dropbox8 Tem 2019

  • CVE-2022-26181
    31İzleyin

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:1

    YüksekCVSS 7,8İstismar yokEPSS %1

    dropbox · lepton28 Şub 2022

  • CVE-2010-3354
    27İzleyin

    dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Tr

    OrtaCVSS 6,9İstismar yokEPSS %0

    dropbox · dropbox20 Eki 2010

  • CVE-2026-28809
    25İzleyin

    XXE in esaml SAML library allows local file read and potential SSRF

    OrtaCVSS 6,3İstismar yokEPSS %0

    arekinath · esaml23 Mar 2026

  • CVE-2018-12271
    25İzleyin

    An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS.

    OrtaCVSS 6,4İstismar yokEPSS %0

    dropbox · dropbox13 Haz 2018

  • CVE-2014-8889
    23İzleyin

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by down

    OrtaCVSS 5,3İstismar yokEPSS %6

    dropbox · dropbox sdk25 Eyl 2017

  • CVE-2017-7448
    22İzleyin

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of

    OrtaCVSS 5,5İstismar yokEPSS %1

    dropbox · lepton5 Nis 2017

  • CVE-2018-12108
    22İzleyin

    An issue was discovered in Dropbox Lepton 1.2.1.

    OrtaCVSS 5,5İstismar yokEPSS %1

    dropbox · lepton11 Haz 2018

  • CVE-2018-20820
    22İzleyin

    read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an inte

    OrtaCVSS 5,5İstismar yokEPSS %1

    dropbox · lepton23 Nis 2019

  • CVE-2017-8891
    22İzleyin

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct

    OrtaCVSS 5,5İstismar yokEPSS %1

    dropbox · lepton10 May 2017

  • CVE-2018-12446
    14İzleyin

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android.

    DüşükCVSS 3,6İstismar yokEPSS %0

    dropbox · dropbox20 Haz 2018

  • CVE-2018-12445
    12İzleyin

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android.

    DüşükCVSS 3,1İstismar yokEPSS %0

    dropbox · dropbox20 Haz 2018