Vulnerabilities > Linecorp > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-25 CVE-2023-39740 Unspecified vulnerability in Linecorp Onigiriya-Musubee 13.6.1
The leakage of the client secret in Onigiriya-musubee Line 13.6.1 allows attackers to obtain the channel access token and send crafted broadcast messages.
network
low complexity
linecorp
8.2
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-07-25 CVE-2023-38493 Unspecified vulnerability in Linecorp Armeria
Armeria is a microservice framework Spring supports Matrix variables.
network
low complexity
linecorp
7.5
2022-11-29 CVE-2022-41568 Resource Exhaustion vulnerability in Linecorp Line
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
network
low complexity
linecorp CWE-400
7.5
2022-04-27 CVE-2022-29505 Unspecified vulnerability in Linecorp Line
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
local
low complexity
linecorp
7.8
2021-09-22 CVE-2021-41011 Unspecified vulnerability in Linecorp Line
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions.
network
low complexity
linecorp
7.5
2021-09-08 CVE-2021-36216 Uncontrolled Search Path Element vulnerability in Linecorp Line
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
local
low complexity
linecorp CWE-427
7.8
2021-09-08 CVE-2021-38388 Missing Authorization vulnerability in Linecorp Central Dogma
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
network
low complexity
linecorp CWE-862
8.8
2019-09-19 CVE-2019-6010 Integer Overflow or Wraparound vulnerability in Linecorp Line
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image.
local
low complexity
linecorp CWE-190
7.8
2019-09-12 CVE-2019-6007 Integer Overflow or Wraparound vulnerability in Linecorp Apng-Drawable
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.
network
low complexity
linecorp CWE-190
8.8