Kakao
Products
6- 4 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-51219 | Cri | 0.62 | 9.6 | 0.01 | Jun 3, 2024 | A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header.… | ||
| CVE-2025-9673 | Med | 0.34 | 5.3 | 0.00 | Aug 29, 2025 | A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android… | ||
| CVE-2024-38480 | Med | 0.26 | 4.0 | 0.00 | Jul 1, 2024 | "Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability. | ||
| CVE-2013-7185 | 0.03 | — | 0.02 | Jan 14, 2020 | PotPlayer 1.5.40688: .avi File Memory Corruption | |||
| CVE-2022-4246 | 0.00 | — | 0.00 | Dec 1, 2022 | A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |||
| CVE-2021-40212 | 0.00 | — | 0.01 | Jun 15, 2022 | An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service. | |||
| CVE-2019-9132 | 0.00 | — | 0.01 | Apr 1, 2019 | Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower. | |||
| CVE-2018-16797 | 0.00 | — | 0.04 | Sep 10, 2018 | A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small Data_Chunk_Size value. | |||
| CVE-2014-4903 | 0.00 | — | 0.00 | Oct 21, 2014 | The Kakao Bingo Garden (aka com.mocoga.bingogarden) application 1.0.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |
- risk 0.62cvss 9.6epss 0.01
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to run any attacker-controlled JavaScript within a WebView. The impact was further escalated by triggering another WebView that leaked its access token in a HTTP request header.…
- risk 0.34cvss 5.3epss 0.00
A vulnerability was detected in Kakao 헤이카카오 Hey Kakao App up to 2.17.4 on Android. Affected by this vulnerability is an unknown functionality of the file AndroidManifest.xml of the component com.kakao.i.connect. The manipulation results in improper export of android…
- risk 0.26cvss 4.0epss 0.00
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an external service, which may allow a local attacker to obtain the API key. Note that the users of the app are not directly affected by this vulnerability.
- CVE-2013-7185Jan 14, 2020risk 0.03cvss —epss 0.02
PotPlayer 1.5.40688: .avi File Memory Corruption
- CVE-2022-4246Dec 1, 2022risk 0.00cvss —epss 0.00
A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public…
- CVE-2021-40212Jun 15, 2022risk 0.00cvss —epss 0.01
An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service.
- CVE-2019-9132Apr 1, 2019risk 0.00cvss —epss 0.01
Remote code execution vulnerability exists in KaKaoTalk PC messenger when user clicks specially crafted link in the message window. This affects KaKaoTalk windows version 2.7.5.2024 or lower.
- CVE-2018-16797Sep 10, 2018risk 0.00cvss —epss 0.04
A heap-based buffer overflow in PotPlayerMini.exe in PotPlayer 1.7.8556 allows remote attackers to execute arbitrary code via a .wav file with large BytesPerSec and SamplesPerSec values, and a small Data_Chunk_Size value.
- CVE-2014-4903Oct 21, 2014risk 0.00cvss —epss 0.00
The Kakao Bingo Garden (aka com.mocoga.bingogarden) application 1.0.14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.