
CVE-2020-20093 – RTLO Injection URI Spoofing
https://notcve.org/view.php?id=CVE-2020-20093
23 Mar 2022 — The Facebook Messenger app for iOS 227.0 and prior and Android 228.1.0.10.116 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. Facebook Messenger app para iOS versiones 227.0 y anteriores y Android versión 228.1.0.10.116 y la interfaz de usuario anterior, no representan apropiadamente los mensajes URI para el usuario, lo que resulta en una suplantación de URI por medio de mensajes especialmente diseñados RTLO injecti... • https://packetstorm.news/files/id/166448 •

CVE-2014-6392
https://notcve.org/view.php?id=CVE-2014-6392
15 Sep 2014 — Cross-site scripting (XSS) vulnerability in the Facebook app 14.0 and the Facebook Messenger app 10.0 for iOS allows remote attackers to inject arbitrary web script or HTML via a crafted filename extension that is improperly handled during MIME sniffing of chat traffic. NOTE: the vendor disputes the significance of this report, because the user must accept an interstitial warning before the HTML file content is rendered, and because the HTML content's origin is a sandbox domain ** DISPUTADA ** Vulnerabilida... • http://seclists.org/fulldisclosure/2014/Sep/13 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •