Cryptocat
Products
1- 17 CVEs
Recent CVEs
17| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2013-4103 | Cri | 0.67 | 9.8 | 0.07 | Nov 4, 2019 | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | ||
| CVE-2013-4108 | Cri | 0.64 | 9.8 | 0.02 | Nov 14, 2019 | Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. | ||
| CVE-2013-2260 | Cri | 0.64 | 9.8 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | ||
| CVE-2013-2259 | Cri | 0.64 | 9.8 | 0.04 | Nov 4, 2019 | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | ||
| CVE-2013-4102 | Cri | 0.59 | 9.1 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness | ||
| CVE-2013-2261 | Hig | 0.53 | 7.5 | 0.12 | Nov 4, 2019 | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | ||
| CVE-2013-4105 | Hig | 0.49 | 7.5 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure | ||
| CVE-2013-2257 | Hig | 0.49 | 7.5 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness | ||
| CVE-2013-4104 | Hig | 0.49 | 7.5 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol | ||
| CVE-2013-2262 | Hig | 0.49 | 7.5 | 0.02 | Nov 4, 2019 | Cryptocat strophe.js before 2.0.22 has information disclosure | ||
| CVE-2013-4100 | Hig | 0.49 | 7.5 | 0.02 | Nov 4, 2019 | Cryptocat before 2.0.22 has Remote Denial of Service via username | ||
| CVE-2013-4106 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2019 | A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22. | ||
| CVE-2013-4109 | Med | 0.40 | 6.1 | 0.02 | Nov 14, 2019 | An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165. | ||
| CVE-2013-4107 | Med | 0.40 | 6.1 | 0.01 | Nov 5, 2019 | Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting | ||
| CVE-2013-4110 | Med | 0.35 | 5.3 | 0.02 | Nov 5, 2019 | Cryptocat has an Unspecified Chat Participant User List Disclosure | ||
| CVE-2013-2258 | Med | 0.35 | 5.3 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 has Nickname User Impersonation | ||
| CVE-2013-4101 | Med | 0.35 | 5.3 | 0.01 | Nov 4, 2019 | Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness |
- risk 0.67cvss 9.8epss 0.07
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
- risk 0.64cvss 9.8epss 0.02
Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors.
- risk 0.64cvss 9.8epss 0.02
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
- risk 0.64cvss 9.8epss 0.04
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
- risk 0.59cvss 9.1epss 0.02
Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness
- risk 0.53cvss 7.5epss 0.12
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
- risk 0.49cvss 7.5epss 0.01
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
- risk 0.49cvss 7.5epss 0.02
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
- risk 0.49cvss 7.5epss 0.01
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
- risk 0.49cvss 7.5epss 0.02
Cryptocat strophe.js before 2.0.22 has information disclosure
- risk 0.49cvss 7.5epss 0.02
Cryptocat before 2.0.22 has Remote Denial of Service via username
- risk 0.40cvss 6.1epss 0.01
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
- risk 0.40cvss 6.1epss 0.02
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
- risk 0.40cvss 6.1epss 0.01
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
- risk 0.35cvss 5.3epss 0.02
Cryptocat has an Unspecified Chat Participant User List Disclosure
- risk 0.35cvss 5.3epss 0.01
Cryptocat before 2.0.22 has Nickname User Impersonation
- risk 0.35cvss 5.3epss 0.01
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness