VYPR

Signal Desktop

by Signal

CVEs (3)

  • CVE-2023-24068HigJan 23, 2023
    risk 0.51cvss 7.8epss 0.00

    Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert…

  • CVE-2023-24069LowJan 23, 2023
    risk 0.22cvss 3.3epss 0.01

    Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file…

  • CVE-2019-19954HigDec 24, 2019
    risk 0.00cvss 7.3epss 0.00

    Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.