Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown

CVE-2018-4009

Disclosure Date: April 15, 2019 (last updated November 27, 2024)
An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to improper validation of code signing. A user with local access can use this vulnerability to raise their privileges to root. An attacker would need local access to the machine to successfully exploit this bug.
Attacker Value
Unknown

CVE-2016-10692

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-8115

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.
0
Attacker Value
Unknown

CVE-2018-7265

Disclosure Date: February 20, 2018 (last updated November 26, 2024)
Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.
0
Attacker Value
Unknown

CVE-2018-6823

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
In the VPN client in Mailbutler Shimo before 4.1.5.1 on macOS, the com.feingeist.shimo.helper tool LaunchDaemon implements an unprotected XPC service that can be abused to execute scripts as root.
0
Attacker Value
Unknown

CVE-2017-0249

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
0
Attacker Value
Unknown

CVE-2017-0256

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
0
Attacker Value
Unknown

CVE-2017-0247

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.
0
Attacker Value
Unknown

CVE-2017-6909

Disclosure Date: March 15, 2017 (last updated November 26, 2024)
An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
0
Attacker Value
Unknown

CVE-2015-5659

Disclosure Date: October 11, 2015 (last updated October 05, 2023)
SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x before 2.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0