Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown
CVE-2018-3988
Disclosure Date: December 10, 2018 (last updated November 27, 2024)
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
0
Attacker Value
Unknown
CVE-2018-16132
Disclosure Date: August 29, 2018 (last updated November 27, 2024)
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.
0
Attacker Value
Unknown
CVE-2018-14023
Disclosure Date: August 20, 2018 (last updated November 27, 2024)
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
0
Attacker Value
Unknown
CVE-2018-11101
Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different vulnerability than CVE-2018-10994. The attacker needs to send HTML code directly as a message, and then reply to that message to trigger this vulnerability. The Signal-Desktop software fails to sanitize specific HTML elements that can be used to inject HTML code into remote chat windows when replying to an HTML message. Specifically the IMG and IFRAME elements can be used to include remote or local resources. For example, the use of an IFRAME element enables full code execution, allowing an attacker to download/upload files, information, etc. The SCRIPT element was also found to be injectable. On the Windows operating system, the CSP fails to prevent remote inclusion of resources via the SMB protocol. In this case, remote execution of JavaScript can be achieved by referencing…
0
Attacker Value
Unknown
CVE-2018-10994
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
0
Attacker Value
Unknown
CVE-2018-9840
Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
0
Attacker Value
Unknown
CVE-2004-1868
Disclosure Date: March 25, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.
0