VYPR

Vendor CVEs

Linecorp

All CVEs

104 total · sorted by risk
  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2026-11746CriJun 22, 2026
    risk 0.61cvss epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2026-11745HigJun 22, 2026
    risk 0.57cvss epss 0.00

    A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…

  • CVE-2019-6007HigSep 12, 2019
    risk 0.57cvss 8.8epss 0.02

    Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.

  • CVE-2026-13133HigAug 10, 2026
    risk 0.55cvss epss 0.00

    A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate…

  • CVE-2024-1143CriFeb 2, 2024
    risk 0.53cvss 9.3epss 0.00

    Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.

  • CVE-2023-45559HigJan 3, 2024
    risk 0.53cvss 8.2epss 0.00

    An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

  • CVE-2023-43305HigDec 8, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43304HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43303HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).

  • CVE-2023-43302HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43301HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-43300HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-39740HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39739HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39737HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39736HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39735HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39734HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39733HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2023-39732HigOct 25, 2023
    risk 0.53cvss 8.2epss 0.01

    The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.

  • CVE-2016-4850HigApr 20, 2017
    risk 0.53cvss 8.1epss 0.02

    LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.

  • CVE-2024-1735CriFeb 26, 2024
    risk 0.52cvss 9.1epss 0.01

    A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.

  • CVE-2022-29505HigApr 27, 2022
    risk 0.51cvss 7.8epss 0.00

    Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.

  • CVE-2021-36216HigSep 8, 2021
    risk 0.51cvss 7.8epss 0.00

    LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.

  • CVE-2019-6010HigSep 19, 2019
    risk 0.51cvss 7.8epss 0.02

    Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image.

  • CVE-2018-0609HigJun 26, 2018
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2016-4831HigJul 12, 2016
    risk 0.51cvss 7.8epss 0.00

    Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

  • CVE-2025-14022HigDec 15, 2025
    risk 0.50cvss 7.7epss 0.00

    LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a…

  • CVE-2023-48134HigNov 16, 2023
    risk 0.49cvss 7.5epss 0.01

    nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.

  • CVE-2023-38849HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38848HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38847HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38846HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2023-38845HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.

  • CVE-2022-41568HigNov 29, 2022
    risk 0.49cvss 7.5epss 0.01

    LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.

  • CVE-2021-41011HigSep 22, 2021
    risk 0.49cvss 7.5epss 0.01

    LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.

  • CVE-2018-0650HigSep 7, 2018
    risk 0.48cvss 7.4epss 0.01

    The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2018-13446HigAug 16, 2018
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…

  • CVE-2018-13435HigAug 16, 2018
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of…

  • CVE-2026-11748MedJun 22, 2026
    risk 0.45cvss epss 0.01

    A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated…

  • CVE-2026-3861MedApr 16, 2026
    risk 0.42cvss 6.5epss 0.00

    LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become…

  • CVE-2023-47373MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47372MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47370MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47368MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47369MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.

  • CVE-2023-47367MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47366MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.

  • CVE-2023-47365MedNov 9, 2023
    risk 0.42cvss 6.5epss 0.00

    The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.

Page 1 of 3