Apache
Apache Cordova: vulnerabilidades y CVE
Apache Cordova tiene 18 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE18
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-21315 | Alta (7.8) | 91% | ⚠ Explotación activa | 16 feb 2021 | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-21315 | Alta (7.8) | 91% | ⚠ Explotación activa | 16 feb 2021 | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1… |
| CVE-2020-11990 | Baja (3.3) | 0.74% | — | 1 dic 2020 | We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious)… |
| CVE-2017-3160 | Alta (7.4) | 3.8% | — | 1 feb 2018 | After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https,… |
| CVE-2014-0073 | Crítica (9.8) | 8.3% | — | 30 oct 2017 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not… |
| CVE-2014-0072 | Alta (7.5) | 7.7% | — | 30 oct 2017 | ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 through 2.9.0 might allow… |
| CVE-2015-1835 | Media (5.3) | 5.9% | — | 27 oct 2017 | Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a… |
| CVE-2016-6799 | Alta (7.5) | 2.6% | — | 9 may 2017 | Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular… |
| CVE-2015-5208 | Media (4.4) | 4.6% | — | 9 may 2016 | Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link. |
| CVE-2015-5207 | Media (5.3) | 2.9% | — | 9 may 2016 | Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods. |
| CVE-2015-8320 | Media (5) | 4.4% | — | 23 nov 2015 | Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value. |
| CVE-2015-5256 | Media (4.3) | 4.2% | — | 23 nov 2015 | Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a… |
| CVE-2014-3502 | Media (4.3) | 5.0% | — | 15 nov 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent. |
| CVE-2014-3501 | Media (4.3) | 3.7% | — | 15 nov 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView. |
| CVE-2014-3500 | Media (6.4) | 4.1% | — | 15 nov 2014 | Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL. |
| CVE-2014-1884 | Alta (7.5) | 8.2% | — | 3 mar 2014 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote attackers to bypass intended device-resource restrictions… |
| CVE-2014-1882 | Alta (7.5) | 12% | — | 3 mar 2014 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME… |
| CVE-2014-1881 | Alta (7.5) | 11% | — | 3 mar 2014 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME… |
| CVE-2012-6637 | Alta (7.5) | 8.9% | — | 3 mar 2014 | Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist protection mechanism via a domain name… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.