Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown

CVE-2018-3988

Disclosure Date: December 10, 2018 (last updated November 27, 2024)
Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on the system.
Attacker Value
Unknown

CVE-2018-16132

Disclosure Date: August 29, 2018 (last updated November 27, 2024)
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.
0
Attacker Value
Unknown

CVE-2018-14023

Disclosure Date: August 20, 2018 (last updated November 27, 2024)
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
0
Attacker Value
Unknown

CVE-2018-11101

Disclosure Date: May 17, 2018 (last updated November 26, 2024)
Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different vulnerability than CVE-2018-10994. The attacker needs to send HTML code directly as a message, and then reply to that message to trigger this vulnerability. The Signal-Desktop software fails to sanitize specific HTML elements that can be used to inject HTML code into remote chat windows when replying to an HTML message. Specifically the IMG and IFRAME elements can be used to include remote or local resources. For example, the use of an IFRAME element enables full code execution, allowing an attacker to download/upload files, information, etc. The SCRIPT element was also found to be injectable. On the Windows operating system, the CSP fails to prevent remote inclusion of resources via the SMB protocol. In this case, remote execution of JavaScript can be achieved by referencing…
0
Attacker Value
Unknown

CVE-2018-10994

Disclosure Date: May 14, 2018 (last updated November 26, 2024)
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
0
Attacker Value
Unknown

CVE-2018-9840

Disclosure Date: April 10, 2018 (last updated November 26, 2024)
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.
0
Attacker Value
Unknown

CVE-2004-1868

Disclosure Date: March 25, 2004 (last updated February 22, 2025)
Stack-based buffer overflow in WinSig.exe in eSignal 7.5 and 7.6 allows remote attackers to execute arbitrary code via a long STREAMQUOTE tag.
0