CVE-2025-5715
- EPSS 0.08%
- Veröffentlicht 06.06.2025 03:00:20
- Zuletzt bearbeitet 17.09.2025 19:21:15
A vulnerability was found in Signal App 7.41.4 on Android. It has been declared as problematic. This vulnerability affects unknown code of the component Biometric Authentication Handler. The manipulation leads to missing critical step in authenticati...
CVE-2022-28345
- EPSS 1.46%
- Veröffentlicht 15.04.2022 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:57:10
The Signal app before 5.34 for iOS allows URI spoofing via RTLO injection. It incorrectly renders RTLO encoded URLs beginning with a non-breaking space, when there is a hash character in the URL. This technique allows a remote unauthenticated attacke...
CVE-2020-5753
- EPSS 0.23%
- Veröffentlicht 20.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:32
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.
CVE-2018-16132
- EPSS 0.3%
- Veröffentlicht 29.08.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:07
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all a...
CVE-2018-9840
- EPSS 0.06%
- Veröffentlicht 10.04.2018 05:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:46
The Open Whisper Signal app before 2.23.2 for iOS allows physically proximate attackers to bypass the screen locker feature via certain rapid sequences of actions that include app opening, clicking on cancel, and using the home button.