- EPSS 0.12%
- Veröffentlicht 01.12.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:25:49
Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled. Apps without these f...
CVE-2023-39956
- EPSS 0.03%
- Veröffentlicht 06.09.2023 21:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:06
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the followin...
CVE-2023-29198
- EPSS 0.15%
- Veröffentlicht 06.09.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:56:41
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in...
CVE-2023-23623
- EPSS 0.5%
- Veröffentlicht 06.09.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:33
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that dir...
CVE-2022-36077
- EPSS 0.09%
- Veröffentlicht 08.11.2022 07:15:09
- Zuletzt bearbeitet 21.11.2024 07:12:19
The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a ...
CVE-2022-29257
- EPSS 0.45%
- Veröffentlicht 13.06.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:49
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update se...
CVE-2022-29247
- EPSS 0.8%
- Veröffentlicht 13.06.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:48
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new...
- EPSS 0.85%
- Veröffentlicht 22.03.2022 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:45:17
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth...
CVE-2021-39184
- EPSS 0.37%
- Veröffentlicht 12.10.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:49
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on...
CVE-2020-26272
- EPSS 0.97%
- Veröffentlicht 28.01.2021 19:15:13
- Zuletzt bearbeitet 27.05.2025 16:15:21
The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the render...