Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Signal MEDIUM 6.4
CVE-2025-5715

A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the compon…

No fix yet
Fix from $1,600 2025-06-06
Signal Desktop HIGH 7.8
CVE-2023-24068

Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directo…

Fix: after 6.2.0
Fix from $1,950 2023-01-23
Signal HIGH 7.5
CVE-2022-28345

The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking spa…

Fix: 5.34+
Fix from $1,950 2022-04-15
Private Messenger MEDIUM 5.3
CVE-2020-5753

Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose curr…

Fix: after 4.59.0
Fix from $1,600 2020-05-20
Signal Desktop HIGH 7.3
CVE-2019-19954

Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe fil…

Fix: 1.29.1+
Fix from $1,950 2019-12-24
Private Messenger CRITICAL 9.8
CVE-2019-17192

The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee c…

Fix: after 4.47.7
Fix from $2,300 2019-10-05
Private Messenger HIGH 7.5
CVE-2019-17191

The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, v…

Fix: 4.47.7+
Fix from $1,950 2019-10-05
Private Messenger MEDIUM 6.5
CVE-2019-9970

Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an …

Fix: after 4.35.3
Fix from $1,600 2019-03-24
Signal HIGH 8.6
CVE-2018-16132

The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large imag…

Fix: after 2.29.0
Fix from $1,950 2018-08-29
Signal Desktop MEDIUM 6.1
CVE-2018-11101

Open Whisper Signal (aka Signal-Desktop) through 1.10.1 allows XSS via a resource location specified in an attribute of a SCRIPT, IFRAME, or IMG elem…

Fix: after 1.10.1
Fix from $1,600 2018-05-17
Signal Desktop MEDIUM 6.1
CVE-2018-10994

js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.

Fix: 1.10.1+
Fix from $1,600 2018-05-14
Signal MEDIUM 6.8
CVE-2018-9840

The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequenc…

Fix: 2.23.2+
Fix from $1,600 2018-04-10