Bitwarden
Top 1K siteProgram Details
- Handle
- bitwarden
- Managed
- No
Response Metrics
- Response Time
- 22 days
Scope (18 targets)
web: 7 mobile: 4 other: 7 In Scope
- 9pjsdv0vpk04 other recognition only
- api.bitwarden.com web recognition only
- bitwarden.com web recognition only
- com.8bit.bitwarden mobile recognition only
- com.bitwarden.authenticator mobile recognition only
- com.bitwarden.authenticator mobile recognition only
- com.x8bit.bitwarden mobile recognition only
- docs.passwordless.dev web recognition only
- help.bitwarden.com web recognition only
- https://addons.mozilla.org/en-US/firefox/addon/bitwarden-password-manager/ other recognition only
- https://addons.opera.com/extensions/details/bitwarden-free-password-manager/ other recognition only
- https://chrome.google.com/webstore/detail/bitwarden-free-password-m/nngceckbapebfimnlniiiahkandclblb?hl=en other recognition only
- https://github.com/bitwarden other recognition only
- https://safari-extensions.apple.com/details/?id=com.bitwarden.safari-LTZ2PFU5D6 other recognition only
- https://www.npmjs.com/package/@bitwarden/mcp-server other recognition only
- identity.bitwarden.com web recognition only
- v4.passwordless.dev web recognition only
- vault.bitwarden.com web recognition only
Known Exploited Vulnerabilities 13CVEs
1 linked to ransomware campaigns
Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption.
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution.
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site.
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site.
Additional Info
- Sources
- hackerone