Show filters
3,556 Total Results
Displaying 181-190 of 3,556
Sort by:
Attacker Value
Unknown

CVE-2023-5455

Disclosure Date: January 10, 2024 (last updated April 25, 2024)
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certain HTTP end-points FreeIPA does not ensure CSRF protection. Due to implementation details one cannot use this flaw for reflection of a cookie representing already logged-in user. An attacker would always have to go through a new authentication attempt.
Attacker Value
Unknown

CVE-2023-7047

Disclosure Date: December 21, 2023 (last updated January 05, 2024)
Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature. This affects only SQL data sources.
Attacker Value
Unknown

CVE-2023-49646

Disclosure Date: December 13, 2023 (last updated December 19, 2023)
Improper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via network access.
Attacker Value
Unknown

CVE-2023-43586

Disclosure Date: December 13, 2023 (last updated December 19, 2023)
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an authenticated user to conduct an escalation of privilege via network access.
Attacker Value
Unknown

CVE-2023-6593

Disclosure Date: December 12, 2023 (last updated December 16, 2023)
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the application to execute entries in a SQL data source without restriction.
Attacker Value
Unknown

CVE-2023-5869

Disclosure Date: December 10, 2023 (last updated April 25, 2024)
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
Attacker Value
Unknown

CVE-2023-6288

Disclosure Date: December 06, 2023 (last updated December 13, 2023)
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
Attacker Value
Unknown

CVE-2023-49314

Disclosure Date: November 28, 2023 (last updated January 30, 2024)
Asana Desktop 2.1.0 on macOS allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode and EnableNodeCliInspectArguments, and thus r3ggi/electroniz3r can be used to perform an attack.
Attacker Value
Unknown

CVE-2023-29069

Disclosure Date: November 22, 2023 (last updated November 30, 2023)
A maliciously crafted DLL file can be forced to install onto a non-default location, and attacker can overwrite parts of the product with malicious DLLs. These files may then have elevated privileges leading to a Privilege Escalation vulnerability.
Attacker Value
Unknown

CVE-2023-43588

Disclosure Date: November 15, 2023 (last updated September 20, 2024)
Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.