Lucene search

K

Twitter Security Vulnerabilities

cve
cve

CVE-2014-6838

The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

6AI Score

0.0005EPSS

2014-09-30 05:55 PM
21
cve
cve

CVE-2016-10511

The Twitter iOS client versions 6.62 and 6.62.1 fail to validate Twitter's server certificates for the /1.1/help/settings.json configuration endpoint, permitting man-in-the-middle attackers the ability to view an application-only OAuth client token and potentially enable unreleased Twitter iOS app ...

5.9CVSS

5.3AI Score

0.001EPSS

2017-09-18 09:29 PM
23
cve
cve

CVE-2017-0911

Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authentication information is passed back to the application using the regis...

5.4CVSS

5.1AI Score

0.001EPSS

2018-02-09 10:29 PM
30
cve
cve

CVE-2019-16263

The Twitter Kit framework through 3.4.2 for iOS does not properly validate the api.twitter.com SSL certificate. Although the certificate chain must contain one of a set of pinned certificates, there are certain implementation errors such as a lack of hostname verification. NOTE: this is an end-of-l...

7.4CVSS

7.1AI Score

0.002EPSS

2019-10-07 12:15 PM
22
cve
cve

CVE-2019-5431

This vulnerability was caused by an incomplete fix to CVE-2017-0911. Twitter Kit for iOS versions 3.0 to 3.4.0 is vulnerable to a callback verification flaw in the "Login with Twitter" component allowing an attacker to provide alternate credentials. In the final step of "Login with Twitter" authent...

5.4CVSS

5.1AI Score

0.001EPSS

2019-05-06 05:29 PM
14
cve
cve

CVE-2020-35774

server/handler/HistogramQueryHandler.scala in Twitter TwitterServer (aka twitter-server) before 20.12.0, in some configurations, allows XSS via the /histograms endpoint.

5.4CVSS

5.1AI Score

0.969EPSS

2020-12-29 06:15 PM
44
7
cve
cve

CVE-2020-5216

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon see...

5.8CVSS

5.9AI Score

0.001EPSS

2020-01-23 03:15 AM
109
cve
cve

CVE-2020-5217

In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon could be injected leading to directive injection. This could ...

5.8CVSS

5.9AI Score

0.001EPSS

2020-01-23 03:15 AM
99
cve
cve

CVE-2023-29218

The Twitter Recommendation Algorithm through ec83d01 allows attackers to cause a denial of service (reduction of reputation score) by arranging for multiple Twitter accounts to coordinate negative signals regarding a target account, such as unfollowing, muting, blocking, and reporting, as exploited...

7.5CVSS

7.4AI Score

0.002EPSS

2023-04-03 09:15 PM
92
2