Electronjs

Electron

38 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 06.09.2023 21:15:11
  • Zuletzt bearbeitet 21.11.2024 07:56:41

Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps using `contextIsolation` and `contextBridge` are affected. This is a context isolation bypass, meaning that code running in...

  • EPSS 0.66%
  • Veröffentlicht 06.09.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:46:33

Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that dir...

  • EPSS 0.52%
  • Veröffentlicht 08.11.2022 07:15:09
  • Zuletzt bearbeitet 21.11.2024 07:12:19

The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a ...

  • EPSS 0.83%
  • Veröffentlicht 13.06.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:58:49

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update se...

  • EPSS 0.95%
  • Veröffentlicht 13.06.2022 21:15:07
  • Zuletzt bearbeitet 21.11.2024 06:58:48

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new...

  • EPSS 0.91%
  • Veröffentlicht 22.03.2022 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:45:17

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth...

  • EPSS 1.02%
  • Veröffentlicht 12.10.2021 19:15:07
  • Zuletzt bearbeitet 21.11.2024 06:18:49

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on...

  • EPSS 1.77%
  • Veröffentlicht 28.01.2021 19:15:13
  • Zuletzt bearbeitet 27.05.2025 16:15:21

The Electron framework lets users write cross-platform desktop applications using JavaScript, HTML and CSS. In versions of Electron IPC prior to 9.4.0, 10.2.0, 11.1.0, and 12.0.0-beta.9, messages sent from the main process to a subframe in the render...

  • EPSS 0.68%
  • Veröffentlicht 06.10.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:05:06

Electron before versions 11.0.0-beta.6, 10.1.2, 9.3.1 or 8.5.2 is vulnerable to a context isolation bypass. Apps using both `contextIsolation` and `sandbox: true` are affected. Apps using both `contextIsolation` and `nodeIntegrationInSubFrames: true`...

  • EPSS 1.32%
  • Veröffentlicht 06.10.2020 18:15:14
  • Zuletzt bearbeitet 21.11.2024 05:05:00

In Electron before versions 11.0.0-beta.1, 10.0.1, 9.3.0 or 8.5.1 the `will-navigate` event that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navi...