Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mattermost mattermost desktop vulnerabilities and exploits
(subscribe to this query)
5.3
CVSSv3
CVE-2018-21265
An issue exists in Mattermost Desktop App prior to 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
Mattermost Mattermost Desktop
5.3
CVSSv3
CVE-2023-5876
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
Mattermost Mattermost Desktop
5.3
CVSSv3
CVE-2023-5875
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
Mattermost Mattermost Desktop
9.8
CVSSv3
CVE-2016-11064
An issue exists in Mattermost Desktop App prior to 3.4.0. Strings could be executed as code via injection.
Mattermost Mattermost Desktop
6.1
CVSSv3
CVE-2020-14454
An issue exists in Mattermost Desktop App prior to 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.
Mattermost Mattermost Desktop
6.5
CVSSv3
CVE-2020-14455
An issue exists in Mattermost Desktop App prior to 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.
Mattermost Mattermost Desktop
7.3
CVSSv3
CVE-2020-14456
An issue exists in Mattermost Desktop App prior to 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.
Mattermost Mattermost Desktop
5.5
CVSSv3
CVE-2023-5339
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
Mattermost Mattermost Desktop
5.4
CVSSv3
CVE-2023-2000
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
Mattermost Mattermost Desktop
8.8
CVSSv3
CVE-2019-20861
An issue exists in Mattermost Desktop App prior to 4.2.2. It allows malicious users to execute arbitrary code via a crafted link.
Mattermost Mattermost Desktop
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
path traversal
CVE-2024-33545
CVE-2024-35725
CVE-2024-32704
overflow
file upload
CVE-2024-0230
CVE-2024-32705
CVE-2024-23692
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »