Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wire HIGH 7.5
CVE-2026-45799

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.3.0 and 7.0.0-alpha03, ByteArrayProtoReader32.skipGroup() an…

Fix: 6.3.0+
Fix from $1,950 2026-07-17
Okhttp Brotli MEDIUM 5.9
CVE-2023-3782

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotl…

No fix yet
Fix from $1,600 2023-07-19
Okio HIGH 7.5
CVE-2023-3635

GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio cli…

Fix: 1.17.6 / 3.4.0+
Fix from $1,950 2023-07-12
Squalor CRITICAL 9.8
CVE-2020-36645

A vulnerability, which was classified as critical, was found in square squalor. This affects an unknown part. The manipulation leads to sql injection…

Patch available
Fix from $2,300 2023-01-07
Okhttp MEDIUM 5.9
CVE-2018-20200

CertificatePinner.java in OkHttp 3.x through 3.12.0 allows man-in-the-middle attackers to bypass certificate pinning by changing SSLContext and the b…

Fix: after 3.12.0
Fix from $1,600 2019-04-18
Retrofit CRITICAL 9.1
CVE-2018-1000844

Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JA…

Fix: 2.5.0+
Fix from $2,300 2018-12-20
Retrofit HIGH 7.5
CVE-2018-1000850

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, met…

Fix: 2.5.0+
Fix from $1,950 2018-12-20
Okhttp MEDIUM 5.9
CVE-2016-2402

OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certi…

Fix: after 2.7.3
Fix from $1,600 2017-01-30
Git Fastclone CRITICAL 9.8
CVE-2015-8969

git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the st…

Fix: 1.0.5+
Fix from $2,300 2016-11-03
Git Fastclone HIGH 8.8
CVE-2015-8968EPSS 5%

git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone fr…

Fix: 1.0.1+
Fix from $1,950 2016-11-03