Vulnerabilities > Matrix

DATE CVE VULNERABILITY TITLE RISK
2022-09-28 CVE-2022-39236 Unspecified vulnerability in Matrix Javascript SDK
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript.
network
low complexity
matrix
5.3
2022-09-13 CVE-2022-39203 Unspecified vulnerability in Matrix IRC Bridge
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix.
network
low complexity
matrix
8.8
2022-09-13 CVE-2022-39202 Improper Privilege Management vulnerability in Matrix IRC Bridge
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix.
network
low complexity
matrix CWE-269
6.3
2022-09-12 CVE-2022-39200 Unspecified vulnerability in Matrix Dendrite
Dendrite is a Matrix homeserver written in Go.
network
low complexity
matrix
5.3
2022-09-02 CVE-2022-31152 Improper Handling of Exceptional Conditions vulnerability in Matrix Synapse
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-755
7.5
2022-08-19 CVE-2022-36009 Unspecified vulnerability in Matrix Dendrite and Gomatrixserverlib
gomatrixserverlib is a Go library for matrix protocol federation.
network
low complexity
matrix
8.8
2022-06-28 CVE-2022-31052 Synapse is an open source home server implementation for the Matrix chat network.
network
low complexity
matrix fedoraproject
6.5
2022-05-05 CVE-2022-29166 Injection vulnerability in Matrix IRC Bridge
matrix-appservice-irc is a Node.js IRC bridge for Matrix.
network
low complexity
matrix CWE-74
8.8
2021-12-14 CVE-2021-44538 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow.
network
low complexity
matrix schildi cinny-project debian CWE-119
critical
9.8
2021-09-13 CVE-2021-40823 Authentication Bypass by Spoofing vulnerability in Matrix Javascript SDK
A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room.
network
high complexity
matrix CWE-290
5.9