CVE-2021-31321
- EPSS 0.19%
- Veröffentlicht 18.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:25
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their custom fork of the rlottie library. A remote attacker might be able to overwrite Telegram's st...
CVE-2021-31320
- EPSS 0.79%
- Veröffentlicht 18.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:25
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorTable function of their custom fork of the rlottie library. A remote attacker might be able ...
CVE-2021-31319
- EPSS 0.15%
- Veröffentlicht 18.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:25
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their custom fork of the rlottie library. A remote attacker might be able to access heap memory ou...
CVE-2021-31318
- EPSS 0.22%
- Veröffentlicht 18.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:25
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function of their custom fork of the rlottie library. A remote attacker might be able to access heap...
CVE-2021-31315
- EPSS 0.13%
- Veröffentlicht 18.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:05:24
Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of the rlottie library. A remote attacker might be able to access Telegram's stack memory out-...
CVE-2021-30496
- EPSS 0.66%
- Veröffentlicht 20.04.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:04:02
The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied message (e.g., in the Persian language) into a channel or group. The crash occurs in MtProtoKi...
CVE-2021-27351
- EPSS 0.18%
- Veröffentlicht 19.02.2021 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:57:49
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.
CVE-2021-27205
- EPSS 0.04%
- Veröffentlicht 12.02.2021 08:15:11
- Zuletzt bearbeitet 21.11.2024 05:57:34
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.
CVE-2021-27204
- EPSS 0.04%
- Veröffentlicht 12.02.2021 08:15:11
- Zuletzt bearbeitet 21.11.2024 05:57:34
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
CVE-2020-12474
- EPSS 0.96%
- Veröffentlicht 01.05.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 04:59:46
Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public URL or a group chat invitation URL.