Show filters
126 Total Results
Displaying 21-30 of 126
Sort by:
Attacker Value
Unknown

CVE-2024-44103

Disclosure Date: September 10, 2024 (last updated September 19, 2024)
DLL hijacking in the management console of Ivanti Workspace Control version 10.18.0.0 and below allows a local authenticated attacker to escalate their privileges.
Attacker Value
Unknown

CVE-2024-42423

Disclosure Date: September 10, 2024 (last updated September 21, 2024)
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
Attacker Value
Unknown

CVE-2024-35143

Disclosure Date: August 04, 2024 (last updated September 12, 2024)
IBM Planning Analytics Local 2.0 and 2.1 connects to a MongoDB server. MongoDB, a document-oriented database system, is listening on the remote port, and it is configured to allow connections without password authentication. A remote attacker can gain unauthorized access to the database. IBM X-Force ID: 292420.
Attacker Value
Unknown

CVE-2024-6286

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
0
Attacker Value
Unknown

CVE-2024-6149

Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
0
Attacker Value
Unknown

CVE-2024-6148

Disclosure Date: July 10, 2024 (last updated September 06, 2024)
Bypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5
Attacker Value
Unknown

CVE-2024-36041

Disclosure Date: July 05, 2024 (last updated July 09, 2024)
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to gain access to the session manager, e.g., use the session-restore feature to execute arbitrary code as the victim (on the next boot) via earlier use of the /tmp directory.
Attacker Value
Unknown

CVE-2024-22260

Disclosure Date: June 27, 2024 (last updated June 28, 2024)
VMware Workspace One UEM update addresses an information exposure vulnerability.  A malicious actor with network access to the Workspace One UEM may be able to perform an attack resulting in an information exposure.
0
Attacker Value
Unknown

CVE-2024-2241

Disclosure Date: March 07, 2024 (last updated March 08, 2024)
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions
0
Attacker Value
Unknown

CVE-2024-1433

Disclosure Date: February 11, 2024 (last updated September 06, 2024)
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp of the component Theme File Handler. The manipulation of the argument pluginId leads to path traversal. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The patch is named 6cdf42916369ebf4ad5bd876c4dfa0170d7b2f01. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-253407. NOTE: This requires write access to user's home or the installation of third party global themes.