Ushareit's vulnerability profile is concentrated in its ShareIt file-sharing application, a consumer-facing product with a notably prominent user base despite the small volume of tracked disclosures. The observed weakness classes center on resource-exhaustion issues, authorization logic flaws, and incomplete vulnerability characterization, reflecting typical challenges in mobile and cross-platform file-transfer utilities. Current severity, exploitation, and disclosure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ushareit over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15234HIGH SHAREit through 4.0.6.177 does not check the full message length from the received packet header (which is used to allocate memory for the next set of data). This could lead to a s | Apr 27, 2020 | 7.5 | 23 | NO | NO |
CVE-2019-14941HIGH SHAREit through 4.0.6.177 does not check the body length from the received packet header (which is used to allocate memory for the next set of data). This could lead to a system de | Apr 27, 2020 | 7.5 | 23 | NO | NO |
CVE-2019-9939HIGH The SHAREit application before 4.0.36 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfe | Mar 22, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9938MEDIUM The SHAREit application before 4.0.42 for Android allows a remote attacker (on the same network or joining public "open" Wi-Fi hotspots created by the application when file transfe | Mar 22, 2019 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ushareit.
Media articles that mention a CVE ID that affects a product developed by Ushareit — matched by CVE ID, not by vendor name.