CVE-2024-53999
- EPSS 1.43%
- Veröffentlicht 03.12.2024 16:15:24
- Zuletzt bearbeitet 27.06.2025 15:16:59
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result...
CVE-2024-43399
- EPSS 0.41%
- Veröffentlicht 19.08.2024 15:15:09
- Zuletzt bearbeitet 20.08.2024 16:21:22
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically, during the...
CVE-2024-41955
- EPSS 14.9%
- Veröffentlicht 31.07.2024 20:15:06
- Zuletzt bearbeitet 15.08.2024 14:10:40
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.
CVE-2024-31215
- EPSS 0.11%
- Veröffentlicht 04.04.2024 16:15:09
- Zuletzt bearbeitet 30.06.2025 13:04:19
Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. A SSRF vulnerability in firebase database check logic. The attacker can cause the server to make a connection to internal-on...
CVE-2024-29190
- EPSS 0.31%
- Veröffentlicht 22.03.2024 23:15:07
- Zuletzt bearbeitet 30.06.2025 13:10:37
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. In version 3.9.5 Beta and prior, MobSF does not perform any input validation when extracting the...
CVE-2023-42261
- EPSS 0.16%
- Veröffentlicht 21.09.2023 22:15:11
- Zuletzt bearbeitet 21.11.2024 08:22:23
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use c...
CVE-2022-41547
- EPSS 1.86%
- Veröffentlicht 18.10.2022 15:15:10
- Zuletzt bearbeitet 10.05.2025 03:15:21
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.