Known Vulnerabilities for products from Cryptocat Project

Listed below are 17 of the newest known vulnerabilities associated with the vendor "Cryptocat Project".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2013-4110 json Cryptocat has an Unspecified Chat Participant User List Disclosure 5.3 - MEDIUM 2019-11-05 2019-11-05
CVE-2013-4109 json An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165. 6.1 - MEDIUM 2019-11-14 2019-11-18
CVE-2013-4108 json Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. 9.8 - CRITICAL 2019-11-14 2019-11-19
CVE-2013-4107 json Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting 6.1 - MEDIUM 2019-11-05 2019-11-05
CVE-2013-4106 json A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22. 6.1 - MEDIUM 2019-11-14 2019-11-18
CVE-2013-4105 json Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure 7.5 - HIGH 2019-11-04 2019-11-05
CVE-2013-4104 json Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol 7.5 - HIGH 2019-11-04 2019-11-06
CVE-2013-4103 json Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input 9.8 - CRITICAL 2019-11-04 2019-11-06
CVE-2013-4102 json Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness 9.1 - CRITICAL 2019-11-04 2019-11-05
CVE-2013-4101 json Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness 5.3 - MEDIUM 2019-11-04 2019-11-08
CVE-2013-4100 json Cryptocat before 2.0.22 has Remote Denial of Service via username 7.5 - HIGH 2019-11-04 2019-11-05
CVE-2013-2262 json Cryptocat strophe.js before 2.0.22 has information disclosure 7.5 - HIGH 2019-11-04 2019-11-05
CVE-2013-2261 json Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure 7.5 - HIGH 2019-11-04 2019-11-05
CVE-2013-2260 json Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness 9.8 - CRITICAL 2019-11-04 2019-11-06
CVE-2013-2259 json Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview 9.8 - CRITICAL 2019-11-04 2019-11-05
CVE-2013-2258 json Cryptocat before 2.0.22 has Nickname User Impersonation 5.3 - MEDIUM 2019-11-04 2019-11-06
CVE-2013-2257 json Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness 7.5 - HIGH 2019-11-04 2019-11-05

Known software with vulnerabilities from Cryptocat Project

Type Vendor Product Version
ApplicationCryptocat ProjectCryptocat-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report