Search

Order by: Limit:

For:

 To:

Run search

 

2021-10-04

Low
 
CVE-2021-41861

Vendor: Telegram Software: Telegram
 
The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. After approximately two to four uses of the self-destruct feature, there is a misleading UI indication that an image was deleted (on both the sender and recipient sides). The images are still present in the /Storage/Emulated/0/Telegram/Telegram Image/ directory.

 

2021-09-06

Medium
 
CVE-2021-40532

Vendor: Telegram Software: Web k alpha
 
Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.

 

2021-07-30

Waiting for details
 
CVE-2021-37596

Updating...
 
Telegram Web K Alpha 0.6.1 allows XSS via a document name.

 

2021-07-17

Waiting for details
 
CVE-2021-36769

Updating...
 
A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the server to receive messages in a different order than they were sent a client.

 

2021-05-18

Low
 
CVE-2021-31315

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

 
Low
 
CVE-2021-31317

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's heap memory out-of-bounds on a victim device via a malicious animated sticker.

 
Low
 
CVE-2021-31318

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

 
Low
 
CVE-2021-31319

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory out-of-bounds on a victim device via a malicious animated sticker.

 
Medium
 
CVE-2021-31320

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorTable function of their custom fork of the rlottie library. A remote attacker might be able to overwrite heap memory out-of-bounds on a victim device via a malicious animated sticker.

 
Medium
 
CVE-2021-31321

Vendor: Telegram Software: Telegram
 
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's stack memory out-of-bounds on a victim device via a malicious animated sticker.

 

 


Copyright 2024, cxsecurity.com

 

Back to Top