Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-39251 Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver ca… Javascript Sdk 19.7.0+ Fix from $1,9502022-09-28 HIGH 7.5 CVE-2022-39248 matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages… Software Development Kit 1.5.1+ Fix from $1,9502022-09-28 MEDIUM 5.3 CVE-2022-39246 matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages… Software Development Kit 1.5.1+ Fix from $1,6002022-09-28 MEDIUM 5.3 CVE-2022-39236 Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Starting with version 17.1.0-rc.1, improperly formed beacon events can disrupt … Javascript Sdk 19.7.0+ Fix from $1,6002022-09-28 HIGH 8.8 CVE-2022-39203 matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the… Matrix Irc Bridge 0.35.0+ Fix from $1,9502022-09-13 MEDIUM 6.3 CVE-2022-39202 matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in… Matrix Irc Bridge 0.35.0+ Fix from $1,6002022-09-13 MEDIUM 5.3 CVE-2022-39200 Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path di… Dendrite 0.9.8+ Fix from $1,6002022-09-12 HIGH 7.5 CVE-2022-31152 Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event … Synapse 1.62.0+ Fix from $1,9502022-09-02 HIGH 8.8 CVE-2022-36009 gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power… Dendrite after 0.9.2 Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-29166 matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing… Matrix Irc Bridge 0.33.2+ Fix from $1,9502022-05-05 MEDIUM 5.9 CVE-2021-40823 A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver p… Javascript Sdk 12.4.1+ Fix from $1,6002021-09-13 MEDIUM 5.9 CVE-2021-40824 A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2… Element 1.2.2+ Fix from $1,6002021-09-13 CRITICAL 9.8 CVE-2021-34813 Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backu… Olm 3.2.3+ Fix from $2,3002021-06-16 HIGH 7.5 CVE-2021-29430 Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send a… Sydent 2.3.0+ Fix from $1,9502021-04-15 MEDIUM 6.5 CVE-2021-29431 Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validatio… Sydent 2.3.0+ Fix from $1,6002021-04-15 MEDIUM 5.7 CVE-2021-29432 Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address. This co… Sydent 2.3.0+ Fix from $1,6002021-04-15 MEDIUM 6.1 CVE-2020-26891 AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote a… Synapse 1.21.0+ Fix from $1,6002020-10-19 CRITICAL 9.8 CVE-2019-18835 Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be c… Synapse 1.5.0+ Fix from $2,3002019-11-08 HIGH 7.5 CVE-2019-11842 An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for … Sydent 0.99.3.1 / 1.0.3+ Fix from $1,9502019-05-09 MEDIUM 5.9 CVE-2019-11340 util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids opt… Sydent 1.0.2+ Fix from $1,6002019-04-19 HIGH 7.5 CVE-2018-12423 In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force. Synapse 0.31.2+ Fix from $1,9502018-06-14 HIGH 7.5 CVE-2018-12291 The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation … Synapse 0.31.1+ Fix from $1,9502018-06-13 HIGH 7.5 CVE-2018-10657 Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, relate… Synapse 0.28.1+ Fix from $1,9502018-05-02