Line

Vendor:

First CVE: Aug 16, 2014 · Active for 11 years

75
Total CVEs
More Total CVEs than 99% of tracked products
6.8
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Line over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 16, 2014
11 years ago
Most Recent CVE
Apr 16, 2026
100 days ago

CVE Severity & Scoring

Line75 CVEs
All CVEs352,708 CVEs
MediumHighCritical
Attack Vector
Local8 (10.7%)
Network64 (85.3%)
Unknown1 (1.3%)
Physical1 (1.3%)
Adjacent Network1 (1.3%)
Attack Complexity
Low68 (90.7%)
High6 (8.0%)
Unknown1 (1.3%)
User Interaction
None62 (82.7%)
Unknown1 (1.3%)
Required12 (16.0%)
Privileges Required
Low30 (40.0%)
High0 (0.0%)
None44 (58.7%)
Unknown1 (1.3%)

Top CVEs

Signals from CVEs in this product scope (75 CVEs).

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Lack of TLS certificate verification in log transmission of a financial module within LINE client for iOS prior to 13.16.0.
Oct 12, 20239.828NONO
LINE client for iOS versions prior to 26.3.0 contains a vulnerability in the in-app browser where opening a crafted web page can repeatedly trigger OS-level dialogs due to insuffic
Apr 16, 20266.526NONO
Due to build misconfiguration in openssl dependency, LINE for Windows before 7.8 is vulnerable to DLL injection that could lead to privilege escalation.
Apr 27, 20227.826NONO
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
Apr 20, 20178.126NONO
An issue in Tamaki_hamanoki Line v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
Jan 3, 20248.225NONO
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Dec 7, 20238.225NONO
LINE client for iOS before 12.17.0 might be crashed by sharing an invalid shared key of e2ee in group chat.
Nov 29, 20227.525NONO
LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
Sep 8, 20217.825NONO
LINE client for iOS prior to 15.4 allows man-in-the-middle attacks due to improper SSL/TLS certificate validation in an integrated financial SDK. The SDK interfered with the applic
Dec 15, 20256.824NONO
An issue in PARK DANDAN mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
Dec 7, 20238.224NONO

Exploit Exposure

Signals from CVEs in this product scope (75 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (75 CVEs).

Media Mentions

Signals from CVEs in this product scope (75 CVEs).

Top CNAs Publishing CVEs For Line

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.8.117.00.4%00
8.8.026.70.4%00
13.6.1506.30.4%00