Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cordova vulnerabilities and exploits
(subscribe to this query)
2.6
CVSSv2
CVE-2015-1835
Apache Cordova Android prior to 3.7.2 and 4.x prior to 4.0.2, when an application does not set explicit values in config.xml, allows remote malicious users to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
Apache Cordova 4.0.1
Apache Cordova 4.0.0
Apache Cordova
5
CVSSv2
CVE-2014-0072
ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) prior to 0.4.2 for iOS and the File-Transfer plugin for iOS from Cordova 2.4.0 up to and including 2.9.0 might allow remote malicious users to spoof SSL servers by lever...
Apache Cordova File Transfer
Apache Cordova
7.5
CVSSv2
CVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) prior to 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 up to and including 2.9.0 does not properly validate callback identifiers, which allo...
Apache Cordova In-app-browser
Apache Cordova
7.5
CVSSv2
CVE-2012-6637
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions do not anchor the end of domain-name regular expressions, which allows remote malicious users to bypass a whitelist protection mechanism via a domain name that contains an acceptable name as...
Apache Cordova 3.3.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.9.0
Adobe Phonegap 2.4.0
Adobe Phonegap
Adobe Phonegap 2.8.0
Adobe Phonegap 2.8.1
7.5
CVSSv2
CVE-2014-1881
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and waits a certain a...
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap 2.8.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
7.5
CVSSv2
CVE-2014-1882
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions allow remote malicious users to bypass intended device-resource restrictions of an event-based bridge via a crafted library clone that leverages IFRAME script execution and directly accesses...
Adobe Phonegap 2.2.0
Adobe Phonegap 2.3.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.0.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
Apache Cordova 3.0.0
Apache Cordova 3.1.0
Apache Cordova 3.2.0
Apache Cordova
Apache Cordova 3.3.0
7.5
CVSSv2
CVE-2014-1884
Apache Cordova 3.3.0 and previous versions and Adobe PhoneGap 2.9.0 and previous versions on Windows Phone 7 and 8 do not properly restrict navigation events, which allows remote malicious users to bypass intended device-resource restrictions via content that is accessed (1) in a...
Apache Cordova 3.0.0
Apache Cordova 3.2.0
Apache Cordova 3.3.0
Apache Cordova 3.1.0
Apache Cordova
Adobe Phonegap 2.0.0
Adobe Phonegap 2.6.0
Adobe Phonegap 2.7.0
Adobe Phonegap 2.8.0
Adobe Phonegap 2.2.0
Adobe Phonegap 2.4.0
Adobe Phonegap 2.5.0
Adobe Phonegap
Adobe Phonegap 2.3.0
Adobe Phonegap 2.1.0
Adobe Phonegap 2.8.1
Adobe Phonegap 2.9.0
5
CVSSv2
CVE-2016-6799
Product: Apache Cordova Android 5.2.2 and previous versions. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a maximum of four ...
Apache Cordova
4.3
CVSSv2
CVE-2015-5208
Apache Cordova iOS prior to 4.0.0 allows remote malicious users to execute arbitrary plugins via a link.
Apache Cordova
5
CVSSv2
CVE-2015-8320
Apache Cordova-Android prior to 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for malicious users to conduct bridge hijacking attacks by predicting a value.
Apache Cordova
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
validation
CVE-2024-34413
CVE-2024-34089
CVE-2024-33408
local
SQL
CVE-2024-0402
CVE-2024-33910
CVE-2024-31848
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »