VYPR
Vendor

Apache Stats

Products
10
CVEs
24
Across products
25
Status
Private

Products

10

Recent CVEs

24
View all 24 CVEs →
  • CVE-2024-52270HigDec 5, 2024
    risk 0.53cvss epss 0.00

    User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will…

  • CVE-2018-12271MedJun 13, 2018
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection…

  • CVE-2018-12108MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.

  • CVE-2017-8891MedMay 10, 2017
    risk 0.36cvss 5.5epss 0.01

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

  • CVE-2017-7448MedApr 5, 2017
    risk 0.36cvss 5.5epss 0.01

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.

  • CVE-2016-6238MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6237MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.

  • CVE-2016-6236MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6235MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.

  • CVE-2016-6234MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.

  • CVE-2014-8889MedSep 26, 2017
    risk 0.35cvss 5.3epss 0.06

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

  • CVE-2026-28809MedMar 23, 2026
    risk 0.27cvss 5.3epss 0.00

    XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled…

  • CVE-2018-12446LowJun 20, 2018
    risk 0.23cvss 3.6epss 0.00

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…

  • CVE-2024-5924Jun 13, 2024
    risk 0.00cvss epss 0.01

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the…

  • CVE-2022-4768Dec 27, 2022
    risk 0.00cvss epss 0.01

    A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible…

  • CVE-2022-4104Nov 28, 2022
    risk 0.00cvss epss 0.00

    A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service.

  • CVE-2022-26181Feb 28, 2022
    risk 0.00cvss epss 0.01

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

  • CVE-2019-12171Jul 8, 2019
    risk 0.00cvss epss 0.01

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

  • CVE-2018-20820Apr 23, 2019
    risk 0.00cvss epss 0.01

    read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

  • CVE-2018-20819Apr 23, 2019
    risk 0.00cvss epss 0.01

    io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check…