Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2021-36513

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may allow attackers to view sensitive information due to an uninitialized value.
Attacker Value
Unknown

CVE-2020-36446

Disclosure Date: August 08, 2021 (last updated February 23, 2025)
An issue was discovered in the signal-simple crate through 2020-11-15 for Rust. There are unconditional implementations of Send and Sync for SyncChannel<T>.
Attacker Value
Unknown

CVE-2020-5753

Disclosure Date: May 20, 2020 (last updated February 21, 2025)
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.
Attacker Value
Unknown

CVE-2019-19954

Disclosure Date: December 24, 2019 (last updated November 27, 2024)
Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.
Attacker Value
Unknown

CVE-2019-17192

Disclosure Date: October 05, 2019 (last updated November 08, 2023)
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs
Attacker Value
Unknown

CVE-2019-17191

Disclosure Date: October 05, 2019 (last updated November 27, 2024)
The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the callee can block eavesdropping.
Attacker Value
Unknown

CVE-2019-15827

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
0
Attacker Value
Unknown

CVE-2017-18535

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The smokesignal plugin before 1.2.7 for WordPress has XSS.
0
Attacker Value
Unknown

CF CLI writes the client id and secret to config file

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
0
Attacker Value
Unknown

CVE-2019-9970

Disclosure Date: March 24, 2019 (last updated November 27, 2024)
Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
0