CVE-2024-42218
- EPSS 0.01%
- Veröffentlicht 06.08.2024 21:16:03
- Zuletzt bearbeitet 12.08.2024 18:27:54
1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.
CVE-2024-42219
- EPSS 0.13%
- Veröffentlicht 06.08.2024 21:16:03
- Zuletzt bearbeitet 12.08.2024 18:30:21
1Password 8 before 8.10.36 for macOS allows local attackers to exfiltrate vault items because XPC inter-process communication validation is insufficient.
CVE-2022-32550
- EPSS 0.34%
- Veröffentlicht 15.06.2022 19:15:11
- Zuletzt bearbeitet 21.11.2024 07:06:36
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password...
CVE-2022-29868
- EPSS 0.03%
- Veröffentlicht 09.05.2022 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:59:51
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affected secret...
CVE-2021-41795
- EPSS 0.34%
- Veröffentlicht 29.09.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:46
The Safari app extension bundled with 1Password for Mac 7.7.0 through 7.8.x before 7.8.7 is vulnerable to authorization bypass. By targeting a vulnerable component of this extension, a malicious web page could read a subset of 1Password vault items t...
CVE-2020-18173
- EPSS 0.08%
- Veröffentlicht 26.07.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:08:27
A DLL injection vulnerability in 1password.dll of 1Password 7.3.712 allows attackers to execute arbitrary code.
CVE-2014-3753
- EPSS 0.22%
- Veröffentlicht 09.01.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 02:08:46
AgileBits 1Password through 1.0.9.340 allows security feature bypass
CVE-2018-13042
- EPSS 11.81%
- Veröffentlicht 05.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:46:17
The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActiv...
CVE-2012-6369
- EPSS 0.23%
- Veröffentlicht 28.12.2012 11:48:44
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Troubleshooting Reporting System feature in AgileBits 1Password 3.9.9 might allow remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header that is not properly handle...