Known Vulnerabilities for products from Mailvelope
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Mailvelope".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-9150 json | Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page. This functionality can b... | 5.3 - MEDIUM | 2019-07-09 | 2019-08-29 |
| CVE-2019-9149 json | Mailvelope prior to 3.3.0 allows private key operations without user interaction via its client-API. By modifying an URL para... | 6.5 - MEDIUM | 2019-07-09 | 2022-04-18 |
| CVE-2019-9148 json | Mailvelope prior to 3.3.0 accepts or operates with invalid PGP public keys: Mailvelope allows importing keys that contain use... | 4.3 - MEDIUM | 2019-07-09 | 2022-04-18 |
| CVE-2019-9147 json | Mailvelope prior to 3.1.0 is vulnerable to a clickjacking attack against the settings page. As the settings page is intended ... | 4.3 - MEDIUM | 2019-07-09 | 2020-08-24 |
Known software with vulnerabilities from Mailvelope
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Mailvelope | Mailvelope | 0.10.0 |