5 results (0.007 seconds)

CVSS: 8.5EPSS: 0%CPEs: 9EXPL: 0

24 Mar 2023 — Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information. Kim Alvefur discovered that insufficient message sender validation in dino-im, a modern XMPP/Jabber client, may result in manipulation of entries in the personal bookmark store without user interaction via a spe... • https://dino.im/security/cve-2023-28686 • CWE-639: Authorization Bypass Through User-Controlled Key •

CVSS: 5.3EPSS: 0%CPEs: 4EXPL: 0

07 Jun 2021 — Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators. Dino versiones 0.1.2 y 0.2.x anteriores a 0.2.1, permite un Salto de Directorio (sólo para la creación de nuevos archivos) por medio de separadores de ruta codificadas por URI • http://www.openwall.com/lists/oss-security/2021/06/07/2 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 1

11 Sep 2019 — Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala. Dino antes del 10-09-2019, no comprueba correctamente la fuente de un mensaje carbons en el archivo module/xep/0280_message_carbons.vala. It was discovered that Dino incorrectly validated inputs. An attacker could use this issue to possibly obtain, inject or remove sensitive information. This update also includes a fix to the encryption implementation in Dino to support 12 byte IVs, in add... • http://www.openwall.com/lists/oss-security/2019/09/12/5 • CWE-346: Origin Validation Error •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 1

11 Sep 2019 — Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala. Dino antes del 10-09-2019, no comprueba la autorización de inserción de lista en el archivo module/roster/module.vala. Multiple vulnerabilities have been discovered in the Dino XMPP client, which could allow spoofing message, manipulation of a user's roster (contact list) and unauthorised sending of message carbons. • http://www.openwall.com/lists/oss-security/2019/09/12/5 • CWE-862: Missing Authorization •

CVSS: 7.5EPSS: 0%CPEs: 6EXPL: 0

11 Sep 2019 — Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala. Dino antes del 10-09-2019, no comprueba correctamente la fuente de un mensaje MAM en el archivo module/xep/0313_message_archive_management.vala. Multiple vulnerabilities have been discovered in the Dino XMPP client, which could allow spoofing message, manipulation of a user's roster (contact list) and unauthorised sending of message carbons. • http://www.openwall.com/lists/oss-security/2019/09/12/5 • CWE-346: Origin Validation Error •