Home/Product/linecorp line
Product

linecorp line

77 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-14023
< 15.19.0
LINE client for iOS prior to 15.19 allows UI spoofing due to inconsistencies between the navigation state and the in-app browser's
3.1LOW
CVE-2025-14022
< 15.4.0
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated
7.7HIGH
CVE-2025-14021
< 14.14.0
The in-app browser in LINE client for iOS versions prior to 14.14 is vulnerable to address bar spoofing, which could allow attacke
4.3MEDIUM
CVE-2025-14020
< 14.20.0
LINE client for Android versions prior to 14.20 contains a UI spoofing vulnerability in the in-app browser where the full-screen s
5.4MEDIUM
CVE-2025-14019
>= 13.8.0 and <= 15.5.0
LINE client for Android versions from 13.8 to 15.5 is vulnerable to UI spoofing in the in-app browser where a specific layout coul
3.4LOW
CVE-2024-5739
>= 14.0.0 and < 14.9.0
The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability
6.1MEDIUM
CVE-2023-48129
all versions
An issue in kimono-oldnew mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the cha
5.4MEDIUM
CVE-2023-48135
all versions
An issue in mimasaka_farm mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the cha
5.4MEDIUM
CVE-2023-48133
all versions
An issue in angel coffee mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chan
5.4MEDIUM
CVE-2023-48132
all versions
An issue in kosei entertainment esportsstudioLegends mini-app on Line v13.6.1 allows attackers to send crafted malicious notificat
5.4MEDIUM
CVE-2023-48131
all versions
An issue in CHIGASAKI BAKERY mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
5.4MEDIUM
CVE-2023-48130
all versions
An issue in GINZA CAFE mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channe
5.4MEDIUM
CVE-2023-48128
all versions
An issue in UNITED BOXING GYM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
5.4MEDIUM
CVE-2023-48127
all versions
An issue in myGAKUYA mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel
5.4MEDIUM
CVE-2023-48126
all versions
An issue in Luxe Beauty Clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of th
5.4MEDIUM
CVE-2023-44001
all versions
An issue in Ailand clinic mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the cha
5.4MEDIUM
CVE-2023-44000
all versions
An issue in Otakara lapis totuka mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of
5.4MEDIUM
CVE-2023-43999
all versions
An issue in COLORFUL_laundry mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
5.4MEDIUM
CVE-2023-43998
all versions
An issue in Books-futaba mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chan
5.4MEDIUM
CVE-2023-43997
all versions
An issue in Yoruichi hobby base mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of t
5.4MEDIUM
CVE-2023-43996
all versions
An issue in Q co ltd mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel
5.4MEDIUM
CVE-2023-43995
all versions
An issue in picot.golf mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channe
5.4MEDIUM
CVE-2023-43994
all versions
An issue in Cleaning_makotoya mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
5.4MEDIUM
CVE-2023-43993
all versions
An issue in smaregi_app_market mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of th
5.4MEDIUM
CVE-2023-43992
all versions
An issue in STOCKMAN GROUP mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the ch
5.4MEDIUM
CVE-2023-43991
all versions
An issue in PRIMA CLINIC mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chan
5.4MEDIUM
CVE-2023-43990
all versions
An issue in cherub-hair mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chann
5.4MEDIUM
CVE-2023-43989
all versions
An issue in mokumoku chohu mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the ch
5.4MEDIUM
CVE-2023-43988
all versions
An issue in nature fitness saijo mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of
5.4MEDIUM
CVE-2023-45559
all versions
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
8.2HIGH
CVE-2023-45561
all versions
An issue in A-WORLD OIRASE BEER_waiting Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel ac
5.3MEDIUM
CVE-2023-43305
all versions
An issue in studio kent mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chann
8.2HIGH
CVE-2023-43304
all versions
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chann
8.2HIGH
CVE-2023-43303
all versions
An issue in craftbeer bar canvas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of
8.2HIGH
CVE-2023-43302
all versions
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel ac
8.2HIGH
CVE-2023-43301
all versions
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
8.2HIGH
CVE-2023-43300
all versions
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the cha
8.2HIGH
CVE-2023-43299
all versions
An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the chann
5.3MEDIUM
CVE-2023-43298
all versions
An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the
5.3MEDIUM
CVE-2023-48134
all versions
nagayama_copabowl Line 13.6.1 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor.
7.5HIGH
CVE-2023-47373
all versions
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victim
6.5MEDIUM
CVE-2023-47372
all versions
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to
6.5MEDIUM
CVE-2023-47370
all versions
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
6.5MEDIUM
CVE-2023-47368
all versions
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims
6.5MEDIUM
CVE-2023-47369
all versions
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
6.5MEDIUM
CVE-2023-47367
all versions
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to vict
6.5MEDIUM
CVE-2023-47366
all versions
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victim
6.5MEDIUM
CVE-2023-47365
all versions
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to
6.5MEDIUM
CVE-2023-47364
all versions
The leakage of channel access token in nagaoka taxi Line 13.6.1 allows remote attackers to send malicious notifications to victims
6.5MEDIUM
CVE-2023-47363
all versions
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victim
6.5MEDIUM
CVE-2015-2968
all versions
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the applic
5.9MEDIUM
CVE-2015-0897
<= 5.0.2
LINE for Android version 5.0.2 and earlier and LINE for iOS version 5.0.0 and earlier are vulnerable to MITM (man-in-the-middle) a
5.9MEDIUM
CVE-2023-38849
all versions
An issue in tire-sales Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
7.5HIGH
CVE-2023-38848
all versions
An issue in rmc R Beauty CLINIC Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
7.5HIGH
CVE-2023-38847
all versions
An issue in CHRISTINA JAPAN Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
7.5HIGH
CVE-2023-38846
all versions
An issue in Marbre Lapin Line v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET request.
7.5HIGH
CVE-2023-38845
all versions
An issue in Anglaise Company Anglaise.Company v.13.6.1 allows a remote attacker to obtain sensitive information via crafted GET re
7.5HIGH
CVE-2023-39731
all versions
The leakage of the client secret in Kaibutsunosato v13.6.1 allows attackers to obtain the channel access token and send crafted br
5.3MEDIUM
CVE-2023-5554
< 13.16.0
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
4.8MEDIUM
CVE-2023-43297
all versions
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
5.4MEDIUM
CVE-2022-41568
< 12.17.0
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
7.5HIGH
CVE-2022-29505
< 7.8
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to
7.8HIGH
CVE-2022-22820
< 7.4.0
Due to the lack of media file checks before rendering, it was possible for an attacker to cause abnormal CPU consumption for messa
5.5MEDIUM
CVE-2021-41011
< 11.15.0
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certai
7.5HIGH
CVE-2021-36216
<= 6.2.1.2289
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
7.8HIGH
CVE-2021-36215
<= 10.21.3
LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
5.3MEDIUM
CVE-2021-36214
< 10.16.3
LINE client for iOS before 10.16.3 allows cross site script with specific header in WebView.
6.1MEDIUM
CVE-2019-6010
>= 4.4.0 and < 9.15.1
Integer overflow vulnerability in LINE(Android) from 4.4.0 to the version before 9.15.1 allows remote attackers to cause a denial
7.8HIGH
CVE-2018-13446
all versions
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass
7.0HIGH
CVE-2018-13435
all versions
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via
7.0HIGH
CVE-2018-13434
all versions
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validatio
6.3MEDIUM
CVE-2018-0609
< 5.8.0
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan h
7.8HIGH
CVE-2018-0518
>= 7.1.3 and <= 7.15
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers
5.9MEDIUM
CVE-2016-4850
<= 4.8.2.1125
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
8.1HIGH
CVE-2016-4831
<= 4.7.0
Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges
7.8HIGH
CVE-2016-1156
<= 4.3.1
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service
5.7MEDIUM
CVE-2013-7144
<= 3.2.1.83
LINE 3.2.1.83 and earlier on Windows and 3.2.1 and earlier on OS X does not verify X.509 certificates from SSL servers, which allo
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin