Vulnerabilities (CVE)

Filtered by vendor Telegram Subscribe
Filtered by product Telegram Messenger
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17715 1 Telegram 1 Telegram Messenger 2018-01-04 6.8 MEDIUM 8.8 HIGH
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to tgnet.dat or tgnet.dat.bak.