Vendor CVEs
Linecorp
All CVEs
104 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-47364 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims | ||
| CVE-2023-47363 | Med | 0.42 | 6.5 | 0.00 | Nov 9, 2023 | The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims. | ||
| CVE-2023-38493 | Hig | 0.42 | 7.5 | 0.01 | Jul 25, 2023 | Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might… | ||
| CVE-2021-43795 | Hig | 0.42 | 7.5 | 0.02 | Dec 2, 2021 | Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing… | ||
| CVE-2018-13434 | Med | 0.41 | 6.3 | 0.00 | Aug 16, 2018 | An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection… | ||
| CVE-2024-5739 | Med | 0.40 | 6.1 | 0.00 | Jun 12, 2024 | The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site… | ||
| CVE-2021-36214 | Med | 0.40 | 6.1 | 0.01 | Jul 13, 2021 | LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView. | ||
| CVE-2019-6002 | Med | 0.40 | 6.1 | 0.01 | Jul 26, 2019 | Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ||
| CVE-2015-2968 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2023 | LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker. | ||
| CVE-2015-0897 | Med | 0.38 | 5.9 | 0.00 | Oct 31, 2023 | LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM… | ||
| CVE-2018-0518 | Med | 0.38 | 5.9 | 0.01 | Feb 23, 2018 | LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | ||
| CVE-2016-1156 | Med | 0.37 | 5.7 | 0.01 | Feb 19, 2016 | LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline. | ||
| CVE-2022-22820 | Med | 0.36 | 5.5 | 0.01 | Jan 20, 2022 | Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4. | ||
| CVE-2025-14020 | Med | 0.35 | 5.4 | 0.00 | Dec 15, 2025 | LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct… | ||
| CVE-2023-48129 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48135 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48133 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48132 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48131 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48130 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48128 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48127 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-48126 | Med | 0.35 | 5.4 | 0.00 | Jan 26, 2024 | An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-44001 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-44000 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43999 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43998 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43997 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43996 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43995 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43994 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43993 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43992 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43991 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43990 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43989 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43988 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2024 | An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43297 | Med | 0.35 | 5.4 | 0.00 | Oct 2, 2023 | An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2021-36215 | Med | 0.35 | 5.3 | 0.01 | Sep 8, 2021 | LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling. | ||
| CVE-2023-45561 | Med | 0.34 | 5.3 | 0.00 | Jan 2, 2024 | An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2023-43299 | Med | 0.34 | 5.3 | 0.01 | Dec 7, 2023 | An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-43298 | Med | 0.34 | 5.3 | 0.01 | Dec 7, 2023 | An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||
| CVE-2023-39731 | Med | 0.34 | 5.3 | 0.00 | Oct 20, 2023 | The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages. | ||
| CVE-2025-11222 | Med | 0.33 | 6.1 | 0.00 | Dec 4, 2025 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft. | ||
| CVE-2026-11752 | Med | 0.31 | — | 0.00 | Jun 19, 2026 | A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to… | ||
| CVE-2023-5554 | Med | 0.31 | 4.8 | 0.00 | Oct 12, 2023 | Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0. | ||
| CVE-2025-14021 | Med | 0.28 | 4.3 | 0.00 | Dec 15, 2025 | The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content. | ||
| CVE-2019-16771 | Med | 0.24 | 4.8 | 0.01 | Dec 6, 2019 | Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has… | ||
| CVE-2025-14019 | Low | 0.22 | 3.4 | 0.00 | Dec 15, 2025 | LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks. | ||
| CVE-2025-14023 | Low | 0.20 | 3.1 | 0.00 | Dec 15, 2025 | LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions. |
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
- risk 0.42cvss 6.5epss 0.00
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
- risk 0.42cvss 7.5epss 0.01
Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might…
- risk 0.42cvss 7.5epss 0.02
Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing…
- risk 0.41cvss 6.3epss 0.00
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection…
- risk 0.40cvss 6.1epss 0.00
The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site…
- risk 0.40cvss 6.1epss 0.01
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting vulnerability in Central Dogma 0.17.0 to 0.40.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- risk 0.38cvss 5.9epss 0.00
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM (man-in-the-middle) attacker.
- risk 0.38cvss 5.9epss 0.00
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be invoked from a script injected by a MITM…
- risk 0.38cvss 5.9epss 0.01
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
- risk 0.37cvss 5.7epss 0.01
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.
- risk 0.36cvss 5.5epss 0.01
Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.
- risk 0.35cvss 5.4epss 0.00
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen security Toast notification is not properly re-displayed when users return from another application, potentially allowing attackers to conduct…
- risk 0.35cvss 5.4epss 0.00
An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.35cvss 5.4epss 0.00
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.35cvss 5.3epss 0.01
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
- risk 0.34cvss 5.3epss 0.00
An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.34cvss 5.3epss 0.01
An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.34cvss 5.3epss 0.01
An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
- risk 0.34cvss 5.3epss 0.00
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
- risk 0.33cvss 6.1epss 0.00
Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft.
- risk 0.31cvss —epss 0.00
A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to…
- risk 0.31cvss 4.8epss 0.00
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
- risk 0.28cvss 4.3epss 0.00
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attackers to execute malicious JavaScript within iframes while displaying trusted URLs, enabling phishing attacks through overlaid malicious content.
- risk 0.24cvss 4.8epss 0.01
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response. This vulnerability has…
- risk 0.22cvss 3.4epss 0.00
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout could obscure the full-screen warning prompt, potentially allowing attackers to conduct phishing attacks.
- risk 0.20cvss 3.1epss 0.00
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's user interface, which could create confusion about the trust context of displayed pages or interactive elements under specific conditions.
Page 2 of 3