Vulnerabilities (CVE)

Filtered by vendor Signal Subscribe
Filtered by product Signal Private Messenger
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-9970 1 Signal 2 Signal-desktop, Signal Private Messenger 2021-07-21 4.3 MEDIUM 6.5 MEDIUM
Open Whisper Signal (aka Signal-Desktop) through 1.23.1 and the Signal Private Messenger application through 4.35.3 for Android are vulnerable to an IDN homograph attack when displaying messages containing URLs. This occurs because the application produces a clickable link even if (for example) Latin and Cyrillic characters exist in the same domain name, and the available font has an identical representation of characters from different alphabets.
CVE-2020-5753 1 Signal 2 Signal, Signal Private Messenger 2021-07-21 5.0 MEDIUM 5.3 MEDIUM
Signal Private Messenger Android v4.59.0 and up and iOS v3.8.1.5 and up allows a remote non-contact to ring a victim's Signal phone and disclose currently used DNS server due to ICE Candidate handling before call is answered or declined.