Vulnerabilities > Linecorp > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-12-02 CVE-2021-43795 Path Traversal vulnerability in Linecorp Armeria
Armeria is an open source microservice framework.
network
low complexity
linecorp CWE-22
5.0
2021-09-22 CVE-2021-41011 Unspecified vulnerability in Linecorp Line
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions.
network
linecorp
4.3
2021-09-08 CVE-2021-36215 Unspecified vulnerability in Linecorp Line
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
network
low complexity
linecorp
5.0
2021-09-08 CVE-2021-36216 Uncontrolled Search Path Element vulnerability in Linecorp Line
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
local
low complexity
linecorp CWE-427
4.6
2021-09-08 CVE-2021-38388 Missing Authorization vulnerability in Linecorp Central Dogma
Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the authorization of the project.
network
low complexity
linecorp CWE-862
6.5
2021-07-13 CVE-2021-36214 Cross-site Scripting vulnerability in Linecorp Line
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
network
linecorp CWE-79
4.3
2019-12-06 CVE-2019-16771 Injection vulnerability in Linecorp Armeria
Versions of Armeria 0.85.0 through and including 0.96.0 are vulnerable to HTTP response splitting, which allows remote attackers to inject arbitrary HTTP headers via CRLF sequences when unsanitized data is used to populate the headers of an HTTP response.
network
low complexity
linecorp CWE-74
5.0
2019-09-19 CVE-2019-6010 Integer Overflow or Wraparound vulnerability in Linecorp Line
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image.
network
linecorp CWE-190
6.8
2019-09-12 CVE-2019-6007 Integer Overflow or Wraparound vulnerability in Linecorp Apng-Drawable
Integer overflow vulnerability in apng-drawable 1.0.0 to 1.6.0 allows an attacker to cause a denial of service (DoS) condition or execute arbitrary code via unspecified vectors.
network
linecorp CWE-190
6.8
2018-09-07 CVE-2018-0650 Improper Certificate Validation vulnerability in Linecorp Line Music 3.1.0
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
network
linecorp CWE-295
5.8