1password
1password: vulnerabilidades y CVE
1password tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-42219 | Alta (7.8) | 0.29% | — | 6 ago 2024 | 1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient. |
| CVE-2024-42218 | Media (4.7) | 0.20% | — | 6 ago 2024 | 1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms. |
| CVE-2022-32550 | Media (4.8) | 0.52% | — | 15 jun 2022 | An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious… |
| CVE-2022-29868 | Media (5.5) | 0.16% | — | 9 may 2022 | 1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running… |
| CVE-2021-41795 | Media (6.5) | 0.93% | — | 29 sept 2021 | The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a… |
| CVE-2020-18173 | Alta (7.8) | 0.47% | — | 26 jul 2021 | A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code. |
| CVE-2014-3753 | Media (5.5) | 0.89% | — | 9 ene 2020 | AgileBits 1Password through 1.0.9.340 allows security feature bypass |
| CVE-2018-13042 | Media (5.9) | 7.9% | — | 5 oct 2018 | The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or… |
| CVE-2012-6369 | Media (4.3) | 0.98% | — | 28 dic 2012 | Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP… |