Flock is a team communication and collaboration platform with a narrowly focused vulnerability footprint concentrated in its core messaging application, where the durable signal centers on web-layer input-handling weaknesses including cross-site scripting, improper input validation, and related neutralization gaps. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flock over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-3202MEDIUM Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark. | Sep 13, 2010 | 4.3 | 24 | NO | YES |
CVE-2010-3262MEDIUM Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed. | Sep 20, 2010 | 4.3 | 17 | NO | NO |
CVE-2010-1236MEDIUM The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does no | Apr 1, 2010 | 4.3 | 15 | NO | NO |
CVE-2009-3007MEDIUM Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary f | Aug 28, 2009 | 4.3 | 15 | NO | NO |
CVE-2006-6954MEDIUM Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE | Jan 29, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flock.
Media articles that mention a CVE ID that affects a product developed by Flock — matched by CVE ID, not by vendor name.