Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dropbox Desktop HIGH 8.8
CVE-2024-5924

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protect…

Mitigation only
Fix from $1,950 2024-06-13
Samly CRITICAL 9.8
CVE-2024-25718

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control b…

Fix: 1.4.0+
Fix from $2,300 2024-02-11
Merou CRITICAL 9.8
CVE-2022-4768

A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_ke…

Fix: 2022-03-28+
Fix from $2,300 2022-12-27
Lepton HIGH 7.8
CVE-2022-26181

Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

No fix yet
Fix from $1,950 2022-02-28
Dropbox HIGH 7.8
CVE-2019-12171

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon s…

No fix yet
Fix from $1,950 2019-07-08
Lepton HIGH 7.8
CVE-2018-20819

io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflo…

Patch available
Fix from $1,950 2019-04-23
Lepton MEDIUM 5.5
CVE-2018-20820

read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overf…

Patch available
Fix from $1,600 2019-04-23
Dropbox MEDIUM 6.4
CVE-2018-12271

An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication…

Mitigation only
Fix from $1,600 2018-06-13
Lepton MEDIUM 5.5
CVE-2018-12108

An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2018-06-11
Dropbox Sdk MEDIUM 5.3
CVE-2014-8889EPSS 6%

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download atta…

No fix yet
Fix from $1,600 2017-09-26
Lepton MEDIUM 5.5
CVE-2017-8891

Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number o…

Patch available
Fix from $1,600 2017-05-10
Lepton MEDIUM 5.5
CVE-2017-7448

The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2017-04-05
Dropbox MEDIUM 6.9
CVE-2010-3354

dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan hors…

Mitigation only
Fix from $1,600 2010-10-20