Vendor CVEs
Linecorp
All CVEs
104 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44487 | Hig | 0.65 | 7.5 | 1.00 | KEV | Oct 10, 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| CVE-2026-11746 | Cri | 0.61 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the… | ||
| CVE-2026-11745 | Hig | 0.57 | — | 0.00 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored… | ||
| CVE-2019-6007 | Hig | 0.57 | 8.8 | 0.02 | Sep 12, 2019 | Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors. | ||
| CVE-2026-13133 | Hig | 0.55 | — | 0.00 | Aug 10, 2026 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate… | ||
| CVE-2024-1143 | Cri | 0.53 | 9.3 | 0.00 | Feb 2, 2024 | Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass. | ||
| CVE-2023-45559 | Hig | 0.53 | 8.2 | 0.00 | Jan 3, 2024 | An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2023-43305 | Hig | 0.53 | 8.2 | 0.01 | Dec 8, 2023 | An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43304 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43303 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic). | ||
| CVE-2023-43302 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43301 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43300 | Hig | 0.53 | 8.2 | 0.01 | Dec 7, 2023 | An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-39740 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39739 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39737 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39736 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39735 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39734 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39733 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2023-39732 | Hig | 0.53 | 8.2 | 0.01 | Oct 25, 2023 | The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2016-4850 | Hig | 0.53 | 8.1 | 0.02 | Apr 20, 2017 | LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code. | ||
| CVE-2024-1735 | Cri | 0.52 | 9.1 | 0.01 | Feb 26, 2024 | A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later. | ||
| CVE-2022-29505 | Hig | 0.51 | 7.8 | 0.00 | Apr 27, 2022 | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation. | ||
| CVE-2021-36216 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2021 | LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection. | ||
| CVE-2019-6010 | Hig | 0.51 | 7.8 | 0.02 | Sep 19, 2019 | Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image. | ||
| CVE-2018-0609 | Hig | 0.51 | 7.8 | 0.01 | Jun 26, 2018 | Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2016-4831 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2016 | Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | ||
| CVE-2025-14022 | Hig | 0.50 | 7.7 | 0.00 | Dec 15, 2025 | LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a… | ||
| CVE-2023-48134 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2023 | nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. | ||
| CVE-2023-38849 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | ||
| CVE-2023-38848 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | ||
| CVE-2023-38847 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | ||
| CVE-2023-38846 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | ||
| CVE-2023-38845 | Hig | 0.49 | 7.5 | 0.01 | Oct 25, 2023 | An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | ||
| CVE-2022-41568 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2022 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | ||
| CVE-2021-41011 | Hig | 0.49 | 7.5 | 0.01 | Sep 22, 2021 | LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information. | ||
| CVE-2018-0650 | Hig | 0.48 | 7.4 | 0.01 | Sep 7, 2018 | The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | ||
| CVE-2018-13446 | Hig | 0.46 | 7.0 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary… | ||
| CVE-2018-13435 | Hig | 0.46 | 7.0 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of… | ||
| CVE-2026-11748 | Med | 0.45 | — | 0.01 | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated… | ||
| CVE-2026-3861 | Med | 0.42 | 6.5 | 0.00 | Apr 16, 2026 | LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become… | ||
| CVE-2023-47373 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47372 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47370 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47368 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47369 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications. | ||
| CVE-2023-47367 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47366 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-47365 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims. |
- risk 0.65cvss 7.5epss 1.00
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
- risk 0.61cvss —epss 0.00
A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…
- risk 0.57cvss —epss 0.00
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored…
- risk 0.57cvss 8.8epss 0.02
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.
- risk 0.55cvss —epss 0.00
A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate…
- risk 0.53cvss 9.3epss 0.00
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
- risk 0.53cvss 8.2epss 0.00
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).
- risk 0.53cvss 8.2epss 0.01
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in REGINA SWEETS&BAKERY Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Matsuya Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Fukunaga_memberscard Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Uomasa_Saiji_news Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in VISION MEAT WORKS TrackDiner10/10_mc Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in TonTon-Tei Line v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.2epss 0.01
The leakage of the client secret in Tokueimaru_waiting Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.53cvss 8.1epss 0.02
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
- risk 0.52cvss 9.1epss 0.01
A vulnerability has been identified in armeria-saml versions less than 1.27.2, allowing the use of malicious SAML messages to bypass authentication. All users who rely on armeria-saml older than version 1.27.2 must upgrade to 1.27.2 or later.
- risk 0.51cvss 7.8epss 0.00
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
- risk 0.51cvss 7.8epss 0.00
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
- risk 0.51cvss 7.8epss 0.02
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image.
- risk 0.51cvss 7.8epss 0.01
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.51cvss 7.8epss 0.00
Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
- risk 0.50cvss 7.7epss 0.00
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a…
- risk 0.49cvss 7.5epss 0.01
nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
- risk 0.49cvss 7.5epss 0.01
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- risk 0.49cvss 7.5epss 0.01
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- risk 0.49cvss 7.5epss 0.01
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- risk 0.49cvss 7.5epss 0.01
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- risk 0.49cvss 7.5epss 0.01
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
- risk 0.49cvss 7.5epss 0.01
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
- risk 0.49cvss 7.5epss 0.01
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.
- risk 0.48cvss 7.4epss 0.01
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- risk 0.46cvss 7.0epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary…
- risk 0.46cvss 7.0epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of…
- risk 0.45cvss —epss 0.01
A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated…
- risk 0.42cvss 6.5epss 0.00
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become…
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Page 1 of 3