Vulnerabilities > Tencent

DATE CVE VULNERABILITY TITLE RISK
2020-04-09 CVE-2020-10551 Improper Privilege Management vulnerability in Tencent Qqbrowser
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe.
local
low complexity
tencent CWE-269
7.2
2020-01-07 CVE-2019-17151 Open Redirect vulnerability in Tencent Wechat
This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9.
network
tencent CWE-601
5.8
2019-07-01 CVE-2019-13125 Permissions, Privileges, and Access Controls vulnerability in Tencent Habomalhunter 2.0.0.2/2.0.0.3
HaboMalHunter through 2.0.0.3 in Tencent Habo allows attackers to evade dynamic malware analysis via PIE compilation.
network
tencent CWE-264
6.8
2019-05-14 CVE-2019-11419 NULL Pointer Dereference vulnerability in Tencent Wechat
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file.
local
low complexity
tencent CWE-476
5.5
2018-08-30 CVE-2018-11616 OS Command Injection vulnerability in Tencent Foxmail 7.2.9.115
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.9.115.
network
tencent CWE-78
6.8
2018-07-08 CVE-2018-13439 XXE vulnerability in Tencent Wechat PAY
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.
network
low complexity
tencent CWE-611
5.0
2012-01-25 CVE-2011-4867 Permissions, Privileges, and Access Controls vulnerability in Tencent Qqpphoto 0.97
The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modify contact information and a password hash via a crafted application.
5.8
2012-01-25 CVE-2011-4865 Permissions, Privileges, and Access Controls vulnerability in Tencent Microblogpad and Wblog
The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attackers to read or modify message drafts and search keywords via a crafted application.
5.8
2012-01-25 CVE-2011-4864 Permissions, Privileges, and Access Controls vulnerability in Tencent Mobileqq 2.2
The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modify messages and a friends list via a crafted application.
5.8
2012-01-25 CVE-2011-4863 Permissions, Privileges, and Access Controls vulnerability in Tencent Qqpimsecure 3.0.2
The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS/MMS messages and a contact list via a crafted application.
5.8