Show filters
3,556 Total Results
Displaying 201-210 of 3,556
Sort by:
Attacker Value
Unknown

CVE-2023-5920

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Mattermost Desktop for MacOS fails to utilize the secure keyboard input functionality provided by macOS, allowing for other processes to read the keyboard input.
Attacker Value
Unknown

CVE-2023-5876

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Mattermost fails to properly validate a RegExp built off the server URL path, allowing an attacker in control of an enrolled server to mount a Denial Of Service.
Attacker Value
Unknown

CVE-2023-5875

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
Attacker Value
Unknown

CVE-2023-5766

Disclosure Date: November 01, 2023 (last updated November 09, 2023)
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from another windows user session on the same host via a specially crafted TCP packet.
Attacker Value
Unknown

CVE-2023-5765

Disclosure Date: November 01, 2023 (last updated February 25, 2025)
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to bypass permissions via data source switching.
Attacker Value
Unknown

CVE-2023-3972

Disclosure Date: November 01, 2023 (last updated February 25, 2025)
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could create the /var/tmp/insights-client directory (owning the directory with read, write, and execute permissions) on the system. After the insights-client is registered by root, an attacker could then control the directory content that insights are using by putting malicious scripts into it and executing arbitrary code as root (trivially bypassing SELinux protections because insights processes are allowed to disable SELinux system-wide).
Attacker Value
Unknown

CVE-2023-5367

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation of privileges or denial of service.
Attacker Value
Unknown

CVE-2023-26300

Disclosure Date: October 18, 2023 (last updated November 01, 2023)
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2023-5339

Disclosure Date: October 17, 2023 (last updated February 25, 2025)
Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including password entry being logged. 
Attacker Value
Unknown

CVE-2023-5166

Disclosure Date: September 25, 2023 (last updated February 25, 2025)
Docker Desktop before 4.23.0 allows Access Token theft via a crafted extension icon URL. This issue affects Docker Desktop: before 4.23.0.