VYPR
Vendor

Bloop

Products
2
CVEs
6
Across products
7
Status
Private

Products

2

Recent CVEs

6
  • CVE-2018-15667HigAug 21, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. It registers and uses the airmail:// URL scheme. The "send" command in the URL scheme allows an external application to send arbitrary emails from an active account without authentication. The handler has no restriction…

  • CVE-2017-17689MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.05

    The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

  • CVE-2017-17688MedMay 16, 2018
    risk 0.39cvss 5.9epss 0.06

    The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature…

  • CVE-2018-15669MedAug 21, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of…

  • CVE-2018-15668MedAug 21, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. The "send" command in the airmail:// URL scheme allows an external application to send arbitrary emails from an active account. URL parameters for the "send" command with the "attachment_" prefix designate attachment…

  • CVE-2018-15670MedAug 21, 2018
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that OpenURL is the default URL handler. A navigation request is processed by the default URL…