Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache cordova vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2015-1835
Apache Cordova Android prior to 3.7.2 and 4.x prior to 4.0.2, when an application does not set explicit values in config.xml, allows remote malicious users to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
Apache Cordova 4.0.1
Apache Cordova 4.0.0
Apache Cordova
7.5
CVSSv3
CVE-2014-0072
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) prior to 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 up to and including 2.9.0 might allow remote malicious users to spoof SSL servers by lever...
Apache Cordova File Transfer
Apache Cordova
9.8
CVSSv3
CVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) prior to 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 up to and including 2.9.0 does not properly validate callback identifiers, which allo...
Apache Cordova In-app-browser
Apache Cordova
NA
CVE-2012-6637
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions do not anchor the end of domain-name regular expressions, which allows remote malicious users to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as...
Apache Cordova 3.3.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.9.0
Adobe Phonegap 2.4.0
Adobe Phonegap
Adobe Phonegap 2.8.0
Adobe Phonegap 2.8.1
NA
CVE-2014-1881
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain a...
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.8.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
NA
CVE-2014-1882
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses...
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
NA
CVE-2014-1884
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote malicious users to bypass intended device-resource restrictions via content that is accessed (1) in a...
Apache Cordova 3.0.0
Apache Cordova 3.2.0
Apache Cordova 3.3.0
Apache Cordova 3.1.0
Apache Cordova
Adobe Phonegap 2.0.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
NA
CVE-2014-3500
Apache Cordova Android prior to 3.5.1 allows remote malicious users to change the start page via a crafted intent URL.
Apache Cordova
7.5
CVSSv3
CVE-2016-6799
Product: Apache Cordova Android 5.2.2 and previous versions. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four ...
Apache Cordova
NA
CVE-2015-8320
Apache Cordova-Android prior to 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for malicious users to conduct bridge hijacking attacks by predicting a value.
Apache Cordova
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
CVE-2006-4304
CVE-2023-26603
CVE-2024-28327
CVE-2023-50363
CVE-2024-21905
template injection
CVE-2024-3400
cross-site request forgery
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »