cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-5876,https://securityvulnerability.io/vulnerability/CVE-2023-5876,Regex DoS from a malicious server enrolled in Desktop,"Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service. ",Mattermost,Mattermost Desktop,5.3,MEDIUM,0.0007300000288523734,false,false,false,false,,false,false,2023-11-02T09:15:00.000Z,0 CVE-2023-5875,https://securityvulnerability.io/vulnerability/CVE-2023-5875,Lack of Hardening against media exploitation from a remote origin,Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server,Mattermost,Mattermost Desktop,5.3,MEDIUM,0.0006300000241026282,false,false,false,false,,false,false,2023-11-02T09:15:00.000Z,0 CVE-2023-5920,https://securityvulnerability.io/vulnerability/CVE-2023-5920,Lack Of Secure Keyboard Entry Protection in MacOS Desktop,"Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input. ",Mattermost,Mattermost Desktop,3.3,LOW,0.0004299999854993075,false,false,false,false,,false,false,2023-11-02T09:15:00.000Z,0 CVE-2016-11064,https://securityvulnerability.io/vulnerability/CVE-2016-11064,,An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.,Mattermost,Mattermost Desktop,9.8,CRITICAL,0.0018700000364333391,false,false,false,false,,false,false,2020-06-19T19:22:33.000Z,0 CVE-2018-21265,https://securityvulnerability.io/vulnerability/CVE-2018-21265,,"An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, audio, and notifications).",Mattermost,Mattermost Desktop,5.3,MEDIUM,0.0008399999933317304,false,false,false,false,,false,false,2020-06-19T16:51:42.000Z,0 CVE-2019-20861,https://securityvulnerability.io/vulnerability/CVE-2019-20861,,An issue was discovered in Mattermost Desktop App before 4.2.2. It allows attackers to execute arbitrary code via a crafted link.,Mattermost,Mattermost Desktop,8.8,HIGH,0.0030799999367445707,false,false,false,false,,false,false,2020-06-19T14:16:54.000Z,0 CVE-2019-20856,https://securityvulnerability.io/vulnerability/CVE-2019-20856,,An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.,Mattermost,Mattermost Desktop,9.8,CRITICAL,0.0023300000466406345,false,false,false,false,,false,false,2020-06-19T14:07:21.000Z,0 CVE-2020-14456,https://securityvulnerability.io/vulnerability/CVE-2020-14456,,"An issue was discovered in Mattermost Desktop App before 4.4.0. The Same Origin Policy is mishandled during access-control decisions for web APIs, aka MMSA-2020-0006.",Mattermost,Mattermost Desktop,7.3,HIGH,0.0009200000204145908,false,false,false,false,,false,false,2020-06-19T13:12:30.000Z,0 CVE-2020-14455,https://securityvulnerability.io/vulnerability/CVE-2020-14455,,"An issue was discovered in Mattermost Desktop App before 4.4.0. Prompting for HTTP Basic Authentication is mishandled, allowing phishing, aka MMSA-2020-0007.",Mattermost,Mattermost Desktop,6.5,MEDIUM,0.0015399999683722854,false,false,false,false,,false,false,2020-06-19T13:11:32.000Z,0 CVE-2020-14454,https://securityvulnerability.io/vulnerability/CVE-2020-14454,,"An issue was discovered in Mattermost Desktop App before 4.4.0. Attackers can open web pages in the desktop application because server redirection is mishandled, aka MMSA-2020-0008.",Mattermost,Mattermost Desktop,6.1,MEDIUM,0.0007800000021234155,false,false,false,false,,false,false,2020-06-19T13:10:48.000Z,0