VYPR

Vendor CVEs

Apache Stats

All CVEs

24 total · sorted by risk
  • CVE-2024-52270HigDec 5, 2024
    risk 0.53cvss epss 0.00

    User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will…

  • CVE-2018-12271MedJun 13, 2018
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection…

  • CVE-2018-12108MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.

  • CVE-2017-8891MedMay 10, 2017
    risk 0.36cvss 5.5epss 0.01

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

  • CVE-2017-7448MedApr 5, 2017
    risk 0.36cvss 5.5epss 0.01

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.

  • CVE-2016-6238MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6237MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.

  • CVE-2016-6236MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.

  • CVE-2016-6235MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.

  • CVE-2016-6234MedFeb 2, 2017
    risk 0.36cvss 5.5epss 0.01

    The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.

  • CVE-2014-8889MedSep 26, 2017
    risk 0.35cvss 5.3epss 0.06

    Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

  • CVE-2026-28809MedMar 23, 2026
    risk 0.27cvss 5.3epss 0.00

    XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled…

  • CVE-2018-12446LowJun 20, 2018
    risk 0.23cvss 3.6epss 0.00

    An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…

  • CVE-2024-5924Jun 13, 2024
    risk 0.00cvss epss 0.01

    Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the…

  • CVE-2022-4768Dec 27, 2022
    risk 0.00cvss epss 0.01

    A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible…

  • CVE-2022-4104Nov 28, 2022
    risk 0.00cvss epss 0.00

    A loop with an unreachable exit condition can be triggered by passing a crafted JPEG file to the Lepton image compression tool, resulting in a denial-of-service.

  • CVE-2022-26181Feb 28, 2022
    risk 0.00cvss epss 0.01

    Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

  • CVE-2019-12171Jul 8, 2019
    risk 0.00cvss epss 0.01

    Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

  • CVE-2018-20820Apr 23, 2019
    risk 0.00cvss epss 0.01

    read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

  • CVE-2018-20819Apr 23, 2019
    risk 0.00cvss epss 0.01

    io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check…

  • CVE-2010-3354Oct 20, 2010
    risk 0.00cvss epss 0.00

    dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

  • CVE-2007-0975Feb 16, 2007
    risk 0.00cvss epss 0.01

    Variable extraction vulnerability in Ian Bezanson Apache Stats before 0.0.3 beta allows attackers to overwrite critical variables, with unknown impact, when the extract function is used on the _REQUEST superglobal array.

  • CVE-2007-0974Feb 16, 2007
    risk 0.00cvss epss 0.01

    Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.

  • CVE-2007-0930Feb 14, 2007
    risk 0.00cvss epss 0.01

    Variable extract vulnerability in Apache Stats before 0.0.3beta allows attackers to modify arbitrary variables and conduct attacks via unknown vectors involving the use of PHP's extract function.