Page 2 of 7 results (0.002 seconds)

CVSS: 5.9EPSS: 2%CPEs: 1EXPL: 1

The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance. La aplicación 1Password 6.8 para Android se ha visto afectada por una vulnerabilidad de denegación de servicio (DoS). Al comenzar las actividades com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity o com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity desde una aplicación externa (ya que están exportadas), es posible provocar el cierre inesperado de la instancia de 1Password. 1Password versions prior to 7.0 suffer from a denial of service vulnerability. • https://www.exploit-db.com/exploits/46165 https://app-updates.agilebits.com/product_history/OPA4 https://www.valbrux.it/blog/2019/01/22/cve-2018-13042-1password-android-7-0-denial-of-service • CWE-20: Improper Input Validation •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 2

Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handled in a View Troubleshooting Report action. Una vulnerabilidad de ejecución de comandos en sitios cruzados (XSS) en el Sistema de Solución de Problemas en AgileBits 1Password v3.9.9 podría permitir a atacantes remotos inyectar secuencias de comandos web o HTML a través de una cabecera HTTP User-Agent modificada que no gestionada adecuadamente en una acción "Ver informe de solución de problemas". • http://packetstormsecurity.org/files/118467/Agilebits-1Password-3.9.9-Cross-Site-Scripting.html http://www.youtube.com/watch?v=A1kPL9ggRi4 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •