Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Line
(Linecorp)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 68 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-07-13 | CVE-2021-36214 | LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView. | Line | 6.1 | ||
2021-09-08 | CVE-2021-36215 | LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling. | Line | 5.3 | ||
2021-09-08 | CVE-2021-36216 | LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection. | Line | 7.8 | ||
2021-09-22 | CVE-2021-41011 | LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information. | Line | 7.5 | ||
2022-01-20 | CVE-2022-22820 | Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for message recipient by sending specially crafted gif image in LINE for Windows before 7.4. | Line | 5.5 | ||
2022-04-27 | CVE-2022-29505 | Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation. | Line | 7.8 | ||
2022-11-29 | CVE-2022-41568 | LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat. | Line | 7.5 | ||
2023-10-02 | CVE-2023-43297 | An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | Line | 5.4 | ||
2023-10-12 | CVE-2023-5554 | Lack of TLS certificate verification in log transmission of a financial module within LINE Client for iOS prior to 13.16.0. | Line | 9.8 | ||
2023-10-25 | CVE-2023-38845 | An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request. | Line | 7.5 |