VendorsLinecorplineall versions
Vulnerabilities

Linecorp LINE 4.3.1 for Mac OS X

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

75CVEs
CVE-2023-5554
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
Published 2023-10-12 · Modified
9.8EPSS 0.002
CVE-2023-43302
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Published 2023-12-07 · Modified
8.2EPSS 0.006
CVE-2023-43301
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Published 2023-12-07 · Modified
8.2EPSS 0.006
CVE-2023-43305
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Published 2023-12-08 · Modified
8.2EPSS 0.006
CVE-2023-43304
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Published 2023-12-07 · Modified
8.2EPSS 0.005
CVE-2023-43300
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Published 2023-12-07 · Modified
8.2EPSS 0.005
CVE-2023-43303
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token (via captured network traffic).
Published 2023-12-07 · Modified
8.2EPSS 0.005
CVE-2023-45559
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
Published 2024-01-03 · Modified
8.2EPSS 0.005
CVE-2016-4850
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
Published 2017-04-20 · Modified
8.1EPSS 0.022
CVE-2019-6010
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial of service (DoS) condition or execute arbitrary code via a specially crafted image.
Published 2019-09-19 · Modified
7.8EPSS 0.017
CVE-2018-0609
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2018-06-26 · Modified
7.8EPSS 0.008
CVE-2022-29505
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
Published 2022-04-27 · Modified
7.8EPSS 0.005
CVE-2021-36216
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
Published 2021-09-08 · Modified
7.8EPSS 0.004
CVE-2016-4831
Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Published 2016-07-12 · Modified
7.8EPSS 0.004
CVE-2025-14022
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the application's network processing, causing server certificate verification to be disabled for a significant portion of network traffic, which could allow a network-adjacent attacker to intercept or modify encrypted communications.
Published 2025-12-15 · Modified
7.7EPSS 0.002
CVE-2021-41011
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this information.
Published 2021-09-22 · Modified
7.5EPSS 0.011
CVE-2023-38845
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Published 2023-10-25 · Modified
7.5EPSS 0.007
CVE-2023-38847
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Published 2023-10-25 · Modified
7.5EPSS 0.007
CVE-2023-38846
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Published 2023-10-25 · Modified
7.5EPSS 0.007
CVE-2023-38849
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Published 2023-10-25 · Modified
7.5EPSS 0.007
CVE-2023-48134
nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
Published 2023-11-16 · Modified
7.5EPSS 0.007
CVE-2023-38848
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
Published 2023-10-25 · Modified
7.5EPSS 0.007
CVE-2022-41568
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
Published 2022-11-29 · Modified
7.5EPSS 0.006
CVE-2026-3861
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insufficient safeguards when handling arbitrary URL schemes, potentially causing the iOS device to become temporarily inoperable.
Published 2026-04-16 · Analyzed
7.1EPSS 0.003
CVE-2018-13435
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred
Published 2018-08-16 · Modified
7.0EPSS 0.004
CVE-2018-13446
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
Published 2018-08-16 · Modified
7.0EPSS 0.004
CVE-2023-47368
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47364
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47372
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47369
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47365
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47363
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47373
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47370
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47367
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2023-47366
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
Published 2023-11-09 · Modified
6.5EPSS 0.004
CVE-2018-13434
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred
Published 2018-08-16 · Modified
6.3EPSS 0.004
CVE-2021-36214
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
Published 2021-07-13 · Modified
6.1EPSS 0.007
CVE-2024-5739
The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site within the in-app browser. The in-app browser is usually opened by tapping on URLs contained in chat messages, and for the attack to be successful, the victim must trigger a click event on a malicious iframe. If an iframe embedded in any website can be controlled by an attacker, this vulnerability could be exploited to capture or alter content displayed in the top frame, as well as user session information. This vulnerability affects LINE client for iOS versions below 14.9.0 and does not affect other LINE clients such as LINE client for Android. Please update LINE client for iOS to version 14.9.0 or higher.
Published 2024-06-12 · Analyzed
6.1EPSS 0.003
CVE-2018-0518
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published 2018-02-23 · Modified
5.9EPSS 0.006
1 / 2Next →