Linecorp
Products
23- 77 CVEs
- 10 CVEs
- 7 CVEs
- 7 CVEs
- 5 CVEs
- 3 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
105| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44487 | Hig | 0.65 | 7.5 | 1.00 | KEV | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| CVE-2026-11746 | Cri | 0.61 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the… | ||
| CVE-2026-11751 | Cri | 0.59 | — | 0.00 | Aug 19, 2026 | A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections. | ||
| CVE-2026-16881 | Hig | 0.57 | — | 0.00 | Aug 4, 2026 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place… | ||
| CVE-2026-11745 | Hig | 0.57 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored… | ||
| CVE-2021-38388 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2021 | Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project. | ||
| CVE-2019-6007 | Hig | 0.57 | 8.8 | 0.02 | Sep 12, 2019 | Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors. | ||
| CVE-2026-13133 | Hig | 0.55 | — | 0.00 | Aug 10, 2026 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate… | ||
| CVE-2024-1143 | Cri | 0.53 | 9.3 | 0.00 | Feb 2, 2024 | Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass. | ||
| CVE-2023-45559 | Hig | 0.53 | 8.2 | 0.00 | Jan 3, 2024 | An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2023-43305 | Hig | 0.53 | 8.2 | 0.01 | Dec 8, 2023 | An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43304 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43303 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic). | ||
| CVE-2023-43302 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43301 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43300 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-39740 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39739 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39737 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39736 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. |
- risk 0.65cvss 7.5epss 1.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- risk 0.61cvss —epss 0.00
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…
- risk 0.59cvss —epss 0.00
A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.
- risk 0.57cvss —epss 0.00
A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate or sandbox externally supplied script content embedded in profile templates. As a result, an attacker who is able to place…
- risk 0.57cvss —epss 0.00
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…
- risk 0.57cvss 8.8epss 0.01
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
- risk 0.57cvss 8.8epss 0.02
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.
- risk 0.55cvss —epss 0.00
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate…
- risk 0.53cvss 9.3epss 0.00
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
- risk 0.53cvss 8.2epss 0.00
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).
- risk 0.53cvss 8.2epss 0.01
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.