CVE-2024-37182
- EPSS 0.33%
- Veröffentlicht 14.06.2024 09:15:10
- Zuletzt bearbeitet 21.11.2024 09:23:22
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.
CVE-2024-36287
- EPSS 0.03%
- Veröffentlicht 14.06.2024 09:15:09
- Zuletzt bearbeitet 21.11.2024 09:21:59
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
CVE-2023-5920
- EPSS 0.08%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:46
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
CVE-2023-5876
- EPSS 0.12%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:41
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
CVE-2023-5875
- EPSS 0.17%
- Veröffentlicht 02.11.2023 09:15:08
- Zuletzt bearbeitet 21.11.2024 08:42:41
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
CVE-2023-5339
- EPSS 0.07%
- Veröffentlicht 17.10.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:33
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged.
CVE-2023-2000
- EPSS 0.21%
- Veröffentlicht 02.05.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 07:57:44
Mattermost Desktop App fails to validate a mattermost server redirection and navigates to an arbitrary website
CVE-2016-11064
- EPSS 0.65%
- Veröffentlicht 19.06.2020 20:15:10
- Zuletzt bearbeitet 21.11.2024 02:45:25
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
CVE-2018-21265
- EPSS 0.2%
- Veröffentlicht 19.06.2020 17:15:13
- Zuletzt bearbeitet 21.11.2024 04:03:19
An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).
CVE-2019-20861
- EPSS 0.73%
- Veröffentlicht 19.06.2020 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:39:33
An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.