Skip to main content

Vendor archive

dropbox CVEs

Beta · best-effort

16 CVEs tagged to vendor dropbox1 Critical, 4 High, 9 Medium, 2 Low, 0 Unrated.

CVE-2024-5924

Published Jun 13, 2024

Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected inst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25718

Published Feb 11, 2024

In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-4768

Published Dec 27, 2022

A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Publ…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-26181

Published Feb 28, 2022

Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12171

Published Jul 8, 2019

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20820

Published Apr 23, 2019

read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20819

Published Apr 23, 2019

io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or po…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12446

Published Jun 20, 2018

An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-12445

Published Jun 20, 2018

An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the c…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-12271

Published Jun 13, 2018

An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LACo…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12108

Published Jun 11, 2018

An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application cra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8889

Published Sep 26, 2017

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-8891

Published May 10, 2017

Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7448

Published Apr 5, 2017

The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and appl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3354

Published Oct 20, 2010

dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the curren…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1