Skip to main content

Vendor/product archive

apache / cordova CVEs

Beta · best-effort

18 CVEs tagged to apache / cordova1 Critical, 8 High, 8 Medium, 1 Low, 0 Unrated.

CVE-2021-21315

Published Feb 16, 2021

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In…

CVSS 7.1 · High
evidence mentions
3
Buzz score
48.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2020-11990

Published Dec 1, 2020

We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to instal…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-3160

Published Feb 1, 2018

After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, si…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1835

Published Oct 27, 2017

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary con…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-6799

Published May 9, 2017

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e(…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5208

Published May 9, 2016

Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5207

Published May 9, 2016

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8320

Published Nov 23, 2015

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5256

Published Nov 23, 2015

Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3502

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL with a crafted URI scheme for an Android intent.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3501

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3500

Published Nov 15, 2014

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

CVSS 6.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-1882

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1881

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an event-based bridge via a crafted…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6637

Published Mar 3, 2014

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expressions, which allows remote attackers to bypass a whitelist…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1