VYPR
Vendor

Apache Stats

Products
11
CVEs
25
Across products
29
Status
Private

Products

11

Recent CVEs

25
View all 25 CVEs →
  • CVE-2024-5924HigJun 13, 2024
    risk 0.57cvss 8.8epss 0.01

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the…

  • CVE-2024-25718CriFeb 11, 2024
    risk 0.57cvss 9.8epss 0.01

    In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry.

  • CVE-2022-26181HigFeb 28, 2022
    risk 0.51cvss 7.8epss 0.01

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

  • CVE-2019-12171HigJul 8, 2019
    risk 0.51cvss 7.8epss 0.01

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

  • CVE-2018-20819HigApr 23, 2019
    risk 0.51cvss 7.8epss 0.01

    io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check…

  • CVE-2018-12271MedJun 13, 2018
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection…

  • CVE-2022-4104MedNov 28, 2022
    risk 0.36cvss 5.5epss 0.00

    A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service.

  • CVE-2018-12108MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.

  • CVE-2017-8891MedMay 10, 2017
    risk 0.36cvss 5.5epss 0.01

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

  • CVE-2017-7448MedApr 5, 2017
    risk 0.36cvss 5.5epss 0.01

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.

  • CVE-2016-6238MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6237MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.

  • CVE-2016-6236MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6235MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.

  • CVE-2016-6234MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.

  • CVE-2014-8889MedSep 26, 2017
    risk 0.35cvss 5.3epss 0.06

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

  • CVE-2026-28809MedMar 23, 2026
    risk 0.27cvss 5.3epss 0.00

    XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled…

  • CVE-2018-12446LowJun 20, 2018
    risk 0.23cvss 3.6epss 0.00

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…

  • CVE-2018-12445LowJun 20, 2018
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the…

  • CVE-2022-4768MedDec 27, 2022
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible…