Vulnerabilities > Linecorp

DATE CVE VULNERABILITY TITLE RISK
2023-10-02 CVE-2023-43297 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Linecorp Line 13.6.1
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
network
low complexity
linecorp CWE-924
5.4
2023-07-25 CVE-2023-38493 Unspecified vulnerability in Linecorp Armeria
Armeria is a microservice framework Spring supports Matrix variables.
network
low complexity
linecorp
7.5
2022-11-29 CVE-2022-41568 Resource Exhaustion vulnerability in Linecorp Line
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
network
low complexity
linecorp CWE-400
7.5
2022-04-27 CVE-2022-29505 Unspecified vulnerability in Linecorp Line
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
local
low complexity
linecorp
7.8
2022-01-20 CVE-2022-22820 Improper Input Validation vulnerability in Linecorp Line
Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4.
local
low complexity
linecorp CWE-20
5.5
2021-09-22 CVE-2021-41011 Unspecified vulnerability in Linecorp Line
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions.
network
low complexity
linecorp
7.5
2021-09-08 CVE-2021-36215 Unspecified vulnerability in Linecorp Line
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
network
low complexity
linecorp
5.3
2021-09-08 CVE-2021-36216 Uncontrolled Search Path Element vulnerability in Linecorp Line
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
local
low complexity
linecorp CWE-427
7.8
2021-09-08 CVE-2021-38388 Missing Authorization vulnerability in Linecorp Central Dogma
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
network
low complexity
linecorp CWE-862
8.8
2021-07-13 CVE-2021-36214 Cross-site Scripting vulnerability in Linecorp Line
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
network
low complexity
linecorp CWE-79
6.1