Cordova

Apache · 18 CVEs

CVE-2021-21315
KEV HIGH

Command Injection Vulnerability

Feb 16, 2021

CVE-2020-11990
LOW

We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications.…

Dec 1, 2020

CVE-2019-0219
CRITICAL

A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's w…

Jan 14, 2020

CVE-2017-3160
HIGH

After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, t…

Feb 1, 2018

CVE-2014-0073
CRITICAL

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) befo…

Oct 30, 2017

CVE-2014-0072
HIGH

ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0…

Oct 30, 2017

CVE-2015-1835
MEDIUM

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xm…

Oct 27, 2017

CVE-2016-6799
HIGH

Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to t…

May 9, 2017

CVE-2015-5208
MEDIUM

Apache Cordova iOS before 4.0.0 allows remote attackers to execute arbitrary plugins via a link.

May 9, 2016

CVE-2015-5207
MEDIUM

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load…

May 9, 2016

CVE-2015-8320
MEDIUM

Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for…

Nov 23, 2015

CVE-2015-5256
MEDIUM

Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript…

Nov 23, 2015

CVE-2014-3502
MEDIUM

Apache Cordova Android before 3.5.1 allows remote attackers to open and send data to arbitrary applications via a URL w…

Nov 15, 2014

CVE-2014-3501
MEDIUM

Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary serve…

Nov 15, 2014

CVE-2014-3500
MEDIUM

Apache Cordova Android before 3.5.1 allows remote attackers to change the start page via a crafted intent URL.

Nov 15, 2014

CVE-2014-1884
HIGH

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict…

Mar 3, 2014

CVE-2014-1882
HIGH

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-…

Mar 3, 2014

CVE-2014-1881
HIGH

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-…

Mar 3, 2014

CVE-2012-6637
HIGH

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier do not anchor the end of domain-name regular expr…

Mar 3, 2014

Showing 1 to 18 of 18 CVEs