VYPR
Vendor

Signal

Products
3
CVEs
16
Across products
21
Status
Private

Products

3

Recent CVEs

16
  • CVE-2019-17192CriOct 5, 2019
    risk 0.64cvss 9.8epss 0.03

    The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified…

  • CVE-2018-16132HigAug 29, 2018
    risk 0.56cvss 8.6epss 0.01

    The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the…

  • CVE-2023-24068HigJan 23, 2023
    risk 0.51cvss 7.8epss 0.00

    Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert…

  • CVE-2022-28345HigApr 15, 2022
    risk 0.49cvss 7.5epss 0.02

    The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthenticated attacker to send legitimate looking…

  • CVE-2019-17191HigOct 5, 2019
    risk 0.49cvss 7.5epss 0.02

    The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The existence of the call is noticeable to the callee; however, the audio channel may be open before the…

  • CVE-2019-9970MedMar 24, 2019
    risk 0.42cvss 6.5epss 0.02

    Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even…

  • CVE-2018-11101MedMay 17, 2018
    risk 0.40cvss 6.1epss 0.01

    Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG element, leading to JavaScript execution after a reply, a different vulnerability than CVE-2018-10994. The attacker needs to send HTML…

  • CVE-2020-5753MedMay 20, 2020
    risk 0.35cvss 5.3epss 0.01

    Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.

  • CVE-2026-8049MedJun 17, 2026
    risk 0.34cvss 5.3epss 0.00

    In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security descriptor and without FILE_DEVICE_SECURE_OPEN. This results in overly permissive default access control, allowing any authenticated local user to obtain a handle…

  • CVE-2018-3988MedDec 10, 2018
    risk 0.31cvss 4.7epss 0.01

    Signal Messenger for Android 4.24.8 may expose private information when using "disappearing messages." If a user uses the photo feature available in the "attach file" menu, then Signal will leave the picture in its own cache directory, which is available to any application on…

  • CVE-2025-5715LowJun 6, 2025
    risk 0.25cvss 3.8epss 0.00

    A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authentication. It is possible to launch…

  • CVE-2023-24069LowJan 23, 2023
    risk 0.22cvss 3.3epss 0.01

    Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file…

  • CVE-2018-14023MedAug 20, 2018
    risk 0.19cvss 4.0epss 0.00

    Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.

  • CVE-2019-19954HigDec 24, 2019
    risk 0.00cvss 7.3epss 0.00

    Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file.

  • CVE-2018-10994MedMay 14, 2018
    risk 0.00cvss 6.1epss 0.01

    js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.

  • CVE-2018-9840MedApr 10, 2018
    risk 0.00cvss 6.8epss 0.00

    The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.