Line\@
by Linecorp
CVEs (77)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41568 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2022 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | ||
| CVE-2021-41011 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2021 | LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information. | ||
| CVE-2018-13446 | Hig | 0.46 | 7.0 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary… | ||
| CVE-2018-13435 | Hig | 0.46 | 7.0 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of… | ||
| CVE-2026-3861 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become… | ||
| CVE-2023-47373 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47372 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47368 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47369 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications. | ||
| CVE-2023-47367 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47366 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47365 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47364 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims | ||
| CVE-2023-47363 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2018-13434 | Med | 0.41 | 6.3 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection… | ||
| CVE-2024-5739 | Med | 0.40 | 6.1 | 0.00 | Jun 12, 2024 | The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site… | ||
| CVE-2021-36214 | Med | 0.40 | 6.1 | 0.01 | Jul 13, 2021 | LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView. | ||
| CVE-2015-2968 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2023 | LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker. | ||
| CVE-2015-0897 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2023 | LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM… |
- risk 0.49cvss 7.5epss 0.01
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
- risk 0.49cvss 7.5epss 0.01
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.
- risk 0.46cvss 7.0epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…
- risk 0.46cvss 7.0epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of…
- risk 0.42cvss 6.5epss 0.00
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become…
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection…
- risk 0.40cvss 6.1epss 0.00
The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site…
- risk 0.40cvss 6.1epss 0.01
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
- risk 0.38cvss 5.9epss 0.00
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.
- risk 0.38cvss 5.9epss 0.00
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM…
Page 2 of 4