Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2023-34658
Disclosure Date: June 29, 2023 (last updated October 08, 2023)
Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.
0
Attacker Value
Unknown
CVE-2023-34006
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marco Milesi Telegram Bot & Channel plugin <= 3.6.2 versions.
0
Attacker Value
Unknown
CVE-2023-26818
Disclosure Date: May 19, 2023 (last updated October 08, 2023)
Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag.
0
Attacker Value
Unknown
CVE-2022-43363
Disclosure Date: December 06, 2022 (last updated November 08, 2023)
Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relationship between the Pastebin information and a possible XSS finding.
0
Attacker Value
Unknown
CVE-2021-41861
Disclosure Date: October 04, 2021 (last updated November 28, 2024)
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.
0
Attacker Value
Unknown
CVE-2021-40532
Disclosure Date: September 06, 2021 (last updated November 28, 2024)
Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
0
Attacker Value
Unknown
CVE-2021-37596
Disclosure Date: July 30, 2021 (last updated February 23, 2025)
Telegram Web K Alpha 0.6.1 allows XSS via a document name.
0
Attacker Value
Unknown
CVE-2021-36769
Disclosure Date: July 17, 2021 (last updated November 28, 2024)
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.
0
Attacker Value
Unknown
CVE-2021-31321
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.
0
Attacker Value
Unknown
CVE-2021-31319
Disclosure Date: May 18, 2021 (last updated February 22, 2025)
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.
0