Matrix kayıtları
matrix üreticisine ait 82 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %91,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation14
- CWE-287 Improper Authentication10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-770 Allocation of Resources Without Limits or Throttling4
- CWE-400 Uncontrolled Resource Consumption4
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
82 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2021-34813İstismar yok | Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room matrix · olm · CWE-787 | Kritik9,8 | — | %4,3 | 16 Haz 2021 |
40Planlayın | CVE-2021-44538İstismar yok | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.matrix · element · CWE-119 | Kritik9,8 | — | %1,9 | 14 Ara 2021 |
39İzleyin | CVE-2019-18835İstismar yok | Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.matrix · synapse · CWE-345 | Kritik9,8 | — | %0,9 | 7 Kas 2019 |
39İzleyin | CVE-2023-38690İstismar yok | matrix-appservice-irc IRC command injection via admin commands containing newlinesmatrix · matrix irc bridge · CWE-20 | Kritik9,8 | — | %0,9 | 4 Ağu 2023 |
36İzleyin | CVE-2023-43656İstismar yok | Sandbox escape for instances that have enabled transformation functions in matrix-hookshotmatrix · hookshot · CWE-74 | Kritik9,0 | — | %0,3 | 27 Eyl 2023 |
35İzleyin | CVE-2018-16515İstismar yok | Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper trmatrix · synapse · CWE-347 | Yüksek8,8 | — | %1,5 | 18 Eyl 2018 |
35İzleyin | CVE-2022-29166İstismar yok | Improper handling of multiline messages in matrix-appservice-ircmatrix · matrix irc bridge · CWE-74 | Yüksek8,8 | — | %1,0 | 5 May 2022 |
35İzleyin | CVE-2022-39203İstismar yok | Parsing issue in matrix-org/node-irc leading to room takeoversmatrix · matrix irc bridge · CWE-269 | Yüksek8,8 | — | %0,8 | 13 Eyl 2022 |
35İzleyin | CVE-2022-36009İstismar yok | Incorrect parsing of access level in gomatrixserverlib and dendritematrix · dendrite · CWE-863 | Yüksek8,8 | — | %0,8 | 19 Ağu 2022 |
34İzleyin | CVE-2024-52815İstismar yok | Synapse allows a a malformed invite to break the invitee's `/sync`matrix · synapse · CWE-20 | Yüksek8,7 | — | %0,6 | 3 Ara 2024 |
32İzleyin | CVE-2021-21332İstismar yok | Cross-site scripting (XSS) vulnerability in the password reset endpointmatrix · synapse · CWE-79 | Yüksek8,2 | — | %1,2 | 26 Mar 2021 |
32İzleyin | CVE-2023-28427İstismar yok | Prototype pollution in matrix-js-sdkmatrix · javascript sdk · CWE-1321 | Yüksek8,2 | — | %1,2 | 28 Mar 2023 |
32İzleyin | CVE-2024-52805İstismar yok | Synapse allows unsupported content types to lead to memory exhaustionmatrix · synapse · CWE-770 | Yüksek8,2 | — | %0,7 | 3 Ara 2024 |
32İzleyin | CVE-2024-53863İstismar yok | Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decodersmatrix · synapse · CWE-434 | Yüksek8,2 | — | %0,6 | 3 Ara 2024 |
31İzleyin | CVE-2020-26890İstismar yok | Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, almatrix · synapse · CWE-20 | Yüksek7,5 | — | %3,0 | 23 Kas 2020 |
31İzleyin | CVE-2019-5885İstismar yok | Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secrematrix · synapse · CWE-330 | Yüksek7,5 | — | %2,4 | 21 Mar 2019 |
31İzleyin | CVE-2018-12423İstismar yok | In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.matrix · synapse | Yüksek7,5 | — | %1,8 | 14 Haz 2018 |
31İzleyin | CVE-2021-29430İstismar yok | Denial of service attack via memory exhaustionmatrix · sydent · CWE-20 | Yüksek7,5 | — | %1,8 | 15 Nis 2021 |
31İzleyin | CVE-2018-12291İstismar yok | The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events fematrix · synapse | Yüksek7,5 | — | %1,8 | 13 Haz 2018 |
31İzleyin | CVE-2019-11842İstismar yok | An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1.matrix · sydent · CWE-338 | Yüksek7,5 | — | %1,8 | 9 May 2019 |
30İzleyin | CVE-2021-41281İstismar yok | Path traversal in Matrix Synapsematrix · synapse · CWE-22 | Yüksek7,5 | — | %1,6 | 23 Kas 2021 |
30İzleyin | CVE-2018-10657İstismar yok | Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusablmatrix · synapse · CWE-20 | Yüksek7,5 | — | %1,5 | 2 May 2018 |
30İzleyin | CVE-2022-39249İstismar yok | Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsmatrix · javascript sdk · CWE-287 | Yüksek7,5 | — | %1,3 | 28 Eyl 2022 |
30İzleyin | CVE-2025-30355İstismar yok | Synapse vulnerable to federation denial of service via malformed eventsmatrix · synapse · CWE-20 | Yüksek7,5 | — | %1,2 | 26 Mar 2025 |
30İzleyin | CVE-2022-39250İstismar yok | Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationmatrix · javascript sdk · CWE-287 | Yüksek7,5 | — | %1,2 | 29 Eyl 2022 |
- CVE-2021-3481340Planlayın
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room
KritikCVSS 9,8İstismar yokEPSS %4matrix · olm16 Haz 2021
- CVE-2021-4453840Planlayın
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.
KritikCVSS 9,8İstismar yokEPSS %2matrix · element14 Ara 2021
- CVE-2019-1883539İzleyin
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs.
KritikCVSS 9,8İstismar yokEPSS %1matrix · synapse7 Kas 2019
- CVE-2023-3869039İzleyin
matrix-appservice-irc IRC command injection via admin commands containing newlines
KritikCVSS 9,8İstismar yokEPSS %1matrix · matrix irc bridge4 Ağu 2023
- CVE-2023-4365636İzleyin
Sandbox escape for instances that have enabled transformation functions in matrix-hookshot
KritikCVSS 9,0İstismar yokEPSS %0matrix · hookshot27 Eyl 2023
- CVE-2018-1651535İzleyin
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper tr
YüksekCVSS 8,8İstismar yokEPSS %2matrix · synapse18 Eyl 2018
- CVE-2022-2916635İzleyin
Improper handling of multiline messages in matrix-appservice-irc
YüksekCVSS 8,8İstismar yokEPSS %1matrix · matrix irc bridge5 May 2022
- CVE-2022-3920335İzleyin
Parsing issue in matrix-org/node-irc leading to room takeovers
YüksekCVSS 8,8İstismar yokEPSS %1matrix · matrix irc bridge13 Eyl 2022
- CVE-2022-3600935İzleyin
Incorrect parsing of access level in gomatrixserverlib and dendrite
YüksekCVSS 8,8İstismar yokEPSS %1matrix · dendrite19 Ağu 2022
- CVE-2024-5281534İzleyin
Synapse allows a a malformed invite to break the invitee's `/sync`
YüksekCVSS 8,7İstismar yokEPSS %1matrix · synapse3 Ara 2024
- CVE-2021-2133232İzleyin
Cross-site scripting (XSS) vulnerability in the password reset endpoint
YüksekCVSS 8,2İstismar yokEPSS %1matrix · synapse26 Mar 2021
- CVE-2023-2842732İzleyin
Prototype pollution in matrix-js-sdk
YüksekCVSS 8,2İstismar yokEPSS %1matrix · javascript sdk28 Mar 2023
- CVE-2024-5280532İzleyin
Synapse allows unsupported content types to lead to memory exhaustion
YüksekCVSS 8,2İstismar yokEPSS %1matrix · synapse3 Ara 2024
- CVE-2024-5386332İzleyin
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
YüksekCVSS 8,2İstismar yokEPSS %1matrix · synapse3 Ara 2024
- CVE-2020-2689031İzleyin
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, al
YüksekCVSS 7,5İstismar yokEPSS %3matrix · synapse23 Kas 2020
- CVE-2019-588531İzleyin
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secre
YüksekCVSS 7,5İstismar yokEPSS %2matrix · synapse21 Mar 2019
- CVE-2018-1242331İzleyin
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
YüksekCVSS 7,5İstismar yokEPSS %2matrix · synapse14 Haz 2018
- CVE-2021-2943031İzleyin
Denial of service attack via memory exhaustion
YüksekCVSS 7,5İstismar yokEPSS %2matrix · sydent15 Nis 2021
- CVE-2018-1229131İzleyin
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events fe
YüksekCVSS 7,5İstismar yokEPSS %2matrix · synapse13 Haz 2018
- CVE-2019-1184231İzleyin
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1.
YüksekCVSS 7,5İstismar yokEPSS %2matrix · sydent9 May 2019
- CVE-2021-4128130İzleyin
Path traversal in Matrix Synapse
YüksekCVSS 7,5İstismar yokEPSS %2matrix · synapse23 Kas 2021
- CVE-2018-1065730İzleyin
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusabl
YüksekCVSS 7,5İstismar yokEPSS %2matrix · synapse2 May 2018
- CVE-2022-3924930İzleyin
Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions
YüksekCVSS 7,5İstismar yokEPSS %1matrix · javascript sdk28 Eyl 2022
- CVE-2025-3035530İzleyin
Synapse vulnerable to federation denial of service via malformed events
YüksekCVSS 7,5İstismar yokEPSS %1matrix · synapse26 Mar 2025
- CVE-2022-3925030İzleyin
Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification
YüksekCVSS 7,5İstismar yokEPSS %1matrix · javascript sdk29 Eyl 2022