Lucene search

K

Dropbox Security Vulnerabilities

cve
cve

CVE-2010-3354

dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

6.7AI Score

0.0004EPSS

2010-10-20 06:00 PM
29
cve
cve

CVE-2014-8889

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

5.3CVSS

5AI Score

0.003EPSS

2017-09-26 01:29 AM
19
cve
cve

CVE-2017-7448

The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.

5.5CVSS

5.4AI Score

0.004EPSS

2017-04-05 11:59 PM
23
cve
cve

CVE-2017-8891

Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

5.5CVSS

5.6AI Score

0.001EPSS

2017-05-10 04:29 PM
27
cve
cve

CVE-2018-12108

An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.

5.5CVSS

5.4AI Score

0.002EPSS

2018-06-11 01:29 PM
24
cve
cve

CVE-2018-12271

An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In o...

6.4CVSS

6.3AI Score

0.002EPSS

2018-06-13 11:29 PM
24
cve
cve

CVE-2018-12445

An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjun...

3.1CVSS

4.5AI Score

0.001EPSS

2018-06-20 12:29 PM
20
cve
cve

CVE-2018-12446

An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the ven...

3.6CVSS

4.5AI Score

0.0004EPSS

2018-06-20 12:29 PM
21
cve
cve

CVE-2018-20819

io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads ...

7.8CVSS

8.2AI Score

0.001EPSS

2019-04-23 02:29 PM
33
cve
cve

CVE-2018-20820

read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

5.5CVSS

5.2AI Score

0.001EPSS

2019-04-23 02:29 PM
32
cve
cve

CVE-2019-12171

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.

7.8CVSS

7.6AI Score

0.002EPSS

2019-07-08 01:15 PM
156
cve
cve

CVE-2022-26181

Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

7.8CVSS

7.6AI Score

0.001EPSS

2022-02-28 07:15 PM
53
cve
cve

CVE-2022-4768

A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack ...

9.8CVSS

9.9AI Score

0.004EPSS

2022-12-27 11:15 PM
36
cve
cve

CVE-2024-5924

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a...

8.8CVSS

8.7AI Score

0.001EPSS

2024-06-13 08:15 PM
76