Line\@
by Linecorp
CVEs (77)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-43994 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43993 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43992 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43991 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43990 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43989 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43988 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43297 | Med | 0.35 | 5.4 | 0.00 | Oct 2, 2023 | An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2021-36215 | Med | 0.35 | 5.3 | 0.01 | Sep 8, 2021 | LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling. | ||
| CVE-2023-45561 | Med | 0.34 | 5.3 | 0.00 | Jan 2, 2024 | An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2023-43299 | Med | 0.34 | 5.3 | 0.01 | Dec 7, 2023 | An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43298 | Med | 0.34 | 5.3 | 0.01 | Dec 7, 2023 | An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-5554 | Med | 0.31 | 4.8 | 0.00 | Oct 12, 2023 | Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0. | ||
| CVE-2025-14021 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2025 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content. | ||
| CVE-2025-14019 | Low | 0.22 | 3.4 | 0.00 | Dec 15, 2025 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks. | ||
| CVE-2025-14023 | Low | 0.20 | 3.1 | 0.00 | Dec 15, 2025 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions. | ||
| CVE-2013-7144 | 0.00 | — | 0.01 | Aug 16, 2014 | LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
- risk 0.35cvss 5.4epss 0.00
An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.35cvss 5.3epss 0.01
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
- risk 0.34cvss 5.3epss 0.00
An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.34cvss 5.3epss 0.01
An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.34cvss 5.3epss 0.01
An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.31cvss 4.8epss 0.00
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
- risk 0.28cvss 4.3epss 0.00
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
- risk 0.22cvss 3.4epss 0.00
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks.
- risk 0.20cvss 3.1epss 0.00
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions.
- CVE-2013-7144Aug 16, 2014risk 0.00cvss —epss 0.01
LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Page 4 of 4