Show filters
3,546 Total Results
Displaying 291-300 of 3,546
Sort by:
Attacker Value
Unknown
CVE-2023-0463
Disclosure Date: January 26, 2023 (last updated November 08, 2023)
The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.
0
Attacker Value
Unknown
CVE-2023-24069
Disclosure Date: January 23, 2023 (last updated February 24, 2025)
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-initiated file deletion, an attacker can still recover the file if it was previously replied to in a conversation. (Local filesystem access is needed by the attacker.) NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
0
Attacker Value
Unknown
CVE-2023-24068
Disclosure Date: January 23, 2023 (last updated November 08, 2023)
Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to modify conversation attachments within the attachments.noindex directory. Client mechanisms fail to validate modifications of existing cached files, resulting in an attacker's ability to insert malicious code into pre-existing attachments or replace them completely. A threat actor can forward the existing attachment in the corresponding conversation to external groups, and the name and size of the file will not change, allowing the malware to masquerade as another file. NOTE: the vendor disputes the relevance of this finding because the product is not intended to protect against adversaries with this degree of local access.
0
Attacker Value
Unknown
CVE-2023-24040
Disclosure Date: January 21, 2023 (last updated February 24, 2025)
dtprintinfo in Common Desktop Environment 1.6 has a bug in the parser of lpstat (an invoked external command) during listing of the names of available printers. This allows low-privileged local users to inject arbitrary printer names via the $HOME/.printers file. This injection allows those users to manipulate the control flow and disclose memory contents on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0
Attacker Value
Unknown
CVE-2023-24039
Disclosure Date: January 21, 2023 (last updated February 24, 2025)
A stack-based buffer overflow in ParseColors in libXm in Common Desktop Environment 1.6 can be exploited by local low-privileged users via the dtprintinfo setuid binary to escalate their privileges to root on Solaris 10 systems. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0
Attacker Value
Unknown
CVE-2022-3515
Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
0
Attacker Value
Unknown
CVE-2023-22472
Disclosure Date: January 09, 2023 (last updated February 24, 2025)
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in an email, chat link, etc). There are currently no known workarounds. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.2.
0
Attacker Value
Unknown
CVE-2022-26964
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.
0
Attacker Value
Unknown
CVE-2022-4287
Disclosure Date: December 21, 2022 (last updated November 08, 2023)
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicious user to access the application.
0
Attacker Value
Unknown
CVE-2022-41121
Disclosure Date: December 13, 2022 (last updated January 02, 2025)
Windows Graphics Component Elevation of Privilege Vulnerability
0