Signal
Signal-desktop: vulnerabilidades y CVE
Signal-desktop tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-24069 | Baja (3.3) | 0.86% | — | 23 ene 2023 | Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively… |
| CVE-2023-24068 | Alta (7.8) | 0.37% | — | 23 ene 2023 | Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing… |
| CVE-2019-19954 | Alta (7.3) | 0.48% | — | 24 dic 2019 | Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. |
| CVE-2019-9970 | Media (6.5) | 1.8% | — | 24 mar 2019 | Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This… |
| CVE-2018-14023 | Media (4) | 0.47% | — | 20 ago 2018 | Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage. |
| CVE-2018-11101 | Media (6.1) | 1.4% | — | 17 may 2018 | Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different… |
| CVE-2018-10994 | Media (6.1) | 1.3% | — | 14 may 2018 | js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL. |