Bitwarden

Bitwarden

Top 100 site
Recognition

Program Details

Handle
bitwarden
Managed
No

Response Metrics

Response Time
24 days
Response Efficiency
98%

Scope (18 targets)

web: 7 mobile: 4 other: 7

Bounty splitting: No

In Scope

  • 9pjsdv0vpk04 other recognition only
  • api.bitwarden.com web recognition only
  • bitwarden.com web recognition only
  • com.8bit.bitwarden mobile recognition only
  • com.bitwarden.authenticator mobile recognition only
  • com.bitwarden.authenticator mobile recognition only
  • com.x8bit.bitwarden mobile recognition only
  • docs.passwordless.dev web recognition only
  • help.bitwarden.com web recognition only
  • https://addons.mozilla.org/en-US/firefox/addon/bitwarden-password-manager/ other recognition only
  • https://addons.opera.com/extensions/details/bitwarden-free-password-manager/ other recognition only
  • https://chrome.google.com/webstore/detail/bitwarden-free-password-m/nngceckbapebfimnlniiiahkandclblb?hl=en other recognition only
  • https://github.com/bitwarden other recognition only
  • https://safari-extensions.apple.com/details/?id=com.bitwarden.safari-LTZ2PFU5D6 other recognition only
  • https://www.npmjs.com/package/@bitwarden/mcp-server other recognition only
  • identity.bitwarden.com web recognition only
  • v4.passwordless.dev web recognition only
  • vault.bitwarden.com web recognition only

Known Exploited Vulnerabilities 13CVEs

1 linked to ransomware campaigns

  • CVE-2010-3765Multiple ProductsOct 6, 202583.2% EPSS

    Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.

  • CVE-2024-9680FirefoxOct 15, 202423.2% EPSS

    Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

  • CVE-2016-9079Firefox, Firefox ESR, and ThunderbirdJun 22, 202387.4% EPSS

    Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.

  • CVE-2015-4495FirefoxMay 25, 202271.3% EPSS

    Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.

  • CVE-2019-11707Firefox and ThunderbirdMay 23, 202237.7% EPSS

    Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

  • CVE-2019-11708Firefox and ThunderbirdMay 23, 202255.9% EPSS

    Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.

  • CVE-2013-1690Firefox and ThunderbirdMar 28, 202269.0% EPSS

    Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.

  • CVE-2022-26486FirefoxMar 7, 20222.3% EPSS

    Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

  • CVE-2022-26485FirefoxMar 7, 202214.3% EPSS

    Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

  • CVE-2013-1675FirefoxMar 3, 20226.7% EPSS

    Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.

and 3 more - view full CISA catalog →

Additional Info

Sources
hackerone