Telegram / Telegram
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-7014 | Improper multimedia file attachment validation in Telegram for Android app | HIGH | 7.1 | Jul 23, 2024 |
| CVE-2023-34658 | Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController. | MEDIUM | 5.3 | Jun 29, 2023 |
| CVE-2023-26818 | Telegram 9.3.1 and 9.4.0 allows attackers to access restricted files, microphone ,or video recording via the DYLD_INSERT_LIBRARIES flag. | MEDIUM | 5.5 | May 19, 2023 |
| CVE-2022-43363 | Telegram Web 15.3.1 allows XSS via a certain payload derived from a Target Corporation website. NOTE: some third parties have been unable to discern any relati… | MEDIUM | 6.1 | Dec 6, 2022 |
| CVE-2021-41861 | The Telegram application 7.5.0 through 7.8.0 for Android does not properly implement image self-destruction, a different vulnerability than CVE-2019-16248. Aft… | LOW | 3.3 | Oct 4, 2021 |
| CVE-2021-36769 | A reordering issue exists in Telegram before 7.8.1 for Android, Telegram before 7.8.3 for iOS, and Telegram Desktop before 2.8.8. An attacker can cause the ser… | MEDIUM | 5.3 | Jul 16, 2021 |
| CVE-2021-31315 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the blit function of their custom fork of… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-31317 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDasher constructor of their custom fork of… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-31318 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCompLayerItem::LOTCompLayerItem function… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-31319 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LOTGradient::populate function of their c… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-31320 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the VGradientCache::generateGradientColorT… | HIGH | 7.1 | May 18, 2021 |
| CVE-2021-31321 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the gray_split_cubic function of their cus… | HIGH | 7.1 | May 18, 2021 |
| CVE-2021-31322 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LOTGradient::populate function of thei… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-31323 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the LottieParserImpl::parseDashProperty fu… | MEDIUM | 5.5 | May 18, 2021 |
| CVE-2021-30496 | The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the victim pastes an attacker-supplied mes… | MEDIUM | 5.7 | Apr 20, 2021 |
| CVE-2021-27351 | The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently act… | MEDIUM | 5.3 | Feb 19, 2021 |
| CVE-2021-27204 | Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure. | MEDIUM | 5.5 | Feb 12, 2021 |
| CVE-2021-27205 | Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure. | MEDIUM | 5.5 | Feb 12, 2021 |
| CVE-2020-12474 | Telegram Desktop through 2.0.1, Telegram through 6.0.1 for Android, and Telegram through 6.0.1 for iOS allow an IDN Homograph attack via Punycode in a public U… | MEDIUM | 6.5 | May 1, 2020 |
| CVE-2020-10570 | The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on me… | MEDIUM | 6.1 | Mar 24, 2020 |
| CVE-2019-16248 | The "delete for" feature in Telegram before 5.11 on Android does not delete shared media files from the Telegram Images directory. In other words, there is a p… | MEDIUM | 5.5 | Sep 11, 2019 |
| CVE-2019-15514 | The Privacy > Phone Number feature in the Telegram app 5.10 for Android and iOS provides an incorrect indication that the access level is Nobody, because attac… | MEDIUM | 5.3 | Aug 23, 2019 |
| CVE-2019-10044 | Telegram Desktop before 1.5.12 on Windows, and the Telegram applications for Android, iOS, and Linux, is vulnerable to an IDN homograph attack when displaying… | HIGH | 8.8 | Mar 25, 2019 |
| CVE-2018-3986 | An exploitable information disclosure vulnerability exists in the "Secret Chats" functionality of the Telegram Android messaging application version 4.9.0. The… | MEDIUM | 5.5 | Jan 3, 2019 |
| CVE-2018-20436 | The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat… | HIGH | 8.1 | Dec 24, 2018 |
Showing 1 to 25 of 27 CVEs