VYPR

Zulip Desktop

by Zulip

CVEs (3)

  • CVE-2020-10857CriFeb 5, 2021
    risk 0.64cvss 9.8epss 0.03

    Zulip Desktop before 5.0.0 improperly uses shell.openExternal and shell.openItem with untrusted content, leading to remote code execution.

  • CVE-2020-24582MedSep 10, 2020
    risk 0.40cvss 6.1epss 0.01

    Zulip Desktop before 5.4.3 allows XSS because string escaping is mishandled during composition of the HTML for the user interface.

  • CVE-2020-10858MedFeb 5, 2021
    risk 0.35cvss 5.3epss 0.01

    Zulip Desktop before 5.0.0 allows attackers to perform recording via the webcam and microphone due to a missing permission request handler.