Show filters
3,546 Total Results
Displaying 251-260 of 3,546
Sort by:
Attacker Value
Unknown
CVE-2022-38730
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition.
0
Attacker Value
Unknown
CVE-2022-37326
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-34292
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.
0
Attacker Value
Unknown
CVE-2022-31647
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.
0
Attacker Value
Unknown
CVE-2023-2282
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector.
0
Attacker Value
Unknown
CVE-2022-40725
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
PingID Desktop prior to the latest released version 1.7.4 contains a vulnerability that can be exploited to bypass the maximum PIN attempts permitted before the time-based lockout is activated.
0
Attacker Value
Unknown
CVE-2023-28124
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Improper usage of symmetric encryption in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow users with access to UI Desktop configuration files to decrypt their content.This vulnerability is fixed in Version 0.62.3 and later.
0
Attacker Value
Unknown
CVE-2023-28123
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A permission misconfiguration in UI Desktop for Windows (Version 0.59.1.71 and earlier) could allow an user to hijack VPN credentials while UID VPN is starting.This vulnerability is fixed in Version 0.62.3 and later.
0
Attacker Value
Unknown
CVE-2023-28122
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
A local privilege escalation (LPE) vulnerability in UI Desktop for Windows (Version 0.59.1.71 and earlier) allows a malicious actor with local access to a Windows device running said application to submit arbitrary commands as SYSTEM.This vulnerability is fixed in Version 0.62.3 and later.
0
Attacker Value
Unknown
CVE-2022-46640
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
0