Lucene search

K

Dino Security Vulnerabilities

cve
cve

CVE-2023-28686

Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive...

7.1CVSS

6.5AI Score

0.003EPSS

2023-03-24 04:15 AM
53
cve
cve

CVE-2021-33896

Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path...

5.3CVSS

5.1AI Score

0.001EPSS

2021-06-07 07:15 PM
47
6
cve
cve

CVE-2019-16235

Dino before 2019-09-10 does not properly check the source of a carbons message in...

7.5CVSS

7.2AI Score

0.003EPSS

2019-09-11 07:15 PM
51
2
cve
cve

CVE-2019-16236

Dino before 2019-09-10 does not check roster push authorization in...

7.5CVSS

7.3AI Score

0.003EPSS

2019-09-11 07:15 PM
39
cve
cve

CVE-2019-16237

Dino before 2019-09-10 does not properly check the source of an MAM message in...

7.5CVSS

7.3AI Score

0.002EPSS

2019-09-11 07:15 PM
48
cve
cve

CVE-2017-18484

Cognitoys Dino devices allow XSS via the...

6.1CVSS

6AI Score

0.001EPSS

2019-08-08 09:15 PM
51
cve
cve

CVE-2017-18485

Cognitoys Dino devices allow profiles_add.html...

5.4CVSS

5.6AI Score

0.001EPSS

2019-08-08 09:15 PM
47
cve
cve

CVE-2014-7633

The Dino Zoo (aka com.tappocket.dinozoostar) application 1.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-10-21 10:55 AM
17
cve
cve

CVE-2014-6997

The Dino Village (aka com.tappocket.dinovillage) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted...

6AI Score

0.0005EPSS

2014-10-16 07:55 PM
17