Show filters
126 Total Results
Displaying 101-110 of 126
Sort by:
Attacker Value
Unknown

CVE-2018-6790

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
An issue was discovered in KDE Plasma Workspace before 5.12.0. dataengines/notifications/notificationsengine.cpp allows remote attackers to discover client IP addresses via a URL in a notification, as demonstrated by the src attribute of an IMG element.
0
Attacker Value
Unknown

CVE-2018-6791

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a shell command, leading to a possibility of arbitrary command execution. An example of an offending volume label is "$(touch b)" -- this will create a file called b in the home folder.
0
Attacker Value
Unknown

CVE-2017-9368

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.
0
Attacker Value
Unknown

CVE-2017-9367

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.
0
Attacker Value
Unknown

CVE-2017-9370

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
An information disclosure / elevation of privilege vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker who has legitimate access to BlackBerry Workspaces to gain access to another user's workspace by making multiple login requests to the server.
0
Attacker Value
Unknown

CVE-2017-3890

Disclosure Date: January 13, 2017 (last updated November 25, 2024)
A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.
Attacker Value
Unknown

CVE-2016-2312

Disclosure Date: December 23, 2016 (last updated November 25, 2024)
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
0
Attacker Value
Unknown

CVE-2016-2205

Disclosure Date: July 12, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read unspecified application files via unknown vectors.
0
Attacker Value
Unknown

CVE-2016-2206

Disclosure Date: July 12, 2016 (last updated November 25, 2024)
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
0
Attacker Value
Unknown

CVE-2015-1484

Disclosure Date: April 22, 2015 (last updated October 05, 2023)
Unquoted Windows search path vulnerability in the agent in Symantec Workspace Streaming (SWS) 6.1 before SP8 MP2 HF7 and 7.5 before SP1 HF4, when AppMgrService.exe is configured as a service, allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.
0