Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Javascript Sdk HIGH 7.5
CVE-2022-39251

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca…

Fix: 19.7.0+
Fix from $1,950 2022-09-28
Software Development Kit HIGH 7.5
CVE-2022-39248

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages…

Fix: 1.5.1+
Fix from $1,950 2022-09-28
Software Development Kit MEDIUM 5.3
CVE-2022-39246

matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages…

Fix: 1.5.1+
Fix from $1,600 2022-09-28
Javascript Sdk MEDIUM 5.3
CVE-2022-39236

Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt …

Fix: 19.7.0+
Fix from $1,600 2022-09-28
Matrix Irc Bridge HIGH 8.8
CVE-2022-39203

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the…

Fix: 0.35.0+
Fix from $1,950 2022-09-13
Matrix Irc Bridge MEDIUM 6.3
CVE-2022-39202

matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in…

Fix: 0.35.0+
Fix from $1,600 2022-09-13
Dendrite MEDIUM 5.3
CVE-2022-39200

Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path di…

Fix: 0.9.8+
Fix from $1,600 2022-09-12
Synapse HIGH 7.5
CVE-2022-31152

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event …

Fix: 1.62.0+
Fix from $1,950 2022-09-02
Dendrite HIGH 8.8
CVE-2022-36009

gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power…

Fix: after 0.9.2
Fix from $1,950 2022-08-19
Matrix Irc Bridge HIGH 8.8
CVE-2022-29166

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing…

Fix: 0.33.2+
Fix from $1,950 2022-05-05
Javascript Sdk MEDIUM 5.9
CVE-2021-40823

A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver p…

Fix: 12.4.1+
Fix from $1,600 2021-09-13
Element MEDIUM 5.9
CVE-2021-40824

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2…

Fix: 1.2.2+
Fix from $1,600 2021-09-13
Olm CRITICAL 9.8
CVE-2021-34813

Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backu…

Fix: 3.2.3+
Fix from $2,300 2021-06-16
Sydent HIGH 7.5
CVE-2021-29430

Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a…

Fix: 2.3.0+
Fix from $1,950 2021-04-15
Sydent MEDIUM 6.5
CVE-2021-29431

Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio…

Fix: 2.3.0+
Fix from $1,600 2021-04-15
Sydent MEDIUM 5.7
CVE-2021-29432

Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This co…

Fix: 2.3.0+
Fix from $1,600 2021-04-15
Synapse MEDIUM 6.1
CVE-2020-26891

AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote a…

Fix: 1.21.0+
Fix from $1,600 2020-10-19
Synapse CRITICAL 9.8
CVE-2019-18835

Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be c…

Fix: 1.5.0+
Fix from $2,300 2019-11-08
Sydent HIGH 7.5
CVE-2019-11842

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for …

Fix: 0.99.3.1 / 1.0.3+
Fix from $1,950 2019-05-09
Sydent MEDIUM 5.9
CVE-2019-11340

util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids opt…

Fix: 1.0.2+
Fix from $1,600 2019-04-19
Synapse HIGH 7.5
CVE-2018-12423

In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

Fix: 0.31.2+
Fix from $1,950 2018-06-14
Synapse HIGH 7.5
CVE-2018-12291

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation …

Fix: 0.31.1+
Fix from $1,950 2018-06-13
Synapse HIGH 7.5
CVE-2018-10657

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, relate…

Fix: 0.28.1+
Fix from $1,950 2018-05-02