Show filters
62 Total Results
Displaying 31-40 of 62
Sort by:
Attacker Value
Unknown
CVE-2020-23451
Disclosure Date: September 15, 2020 (last updated February 22, 2025)
Spiceworks Version <= 7.5.00107 is affected by CSRF which can lead to privilege escalation via "/settings/v1/users" function.
0
Attacker Value
Unknown
CVE-2020-23450
Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Spiceworks Version <= 7.5.00107 is affected by XSS. Any name typed on Custom Groups function is vulnerable to stored XSS as they displayed on http://127.0.0.1/inventory/groups/ without output sanitization.
0
Attacker Value
Unknown
CVE-2019-3813
Disclosure Date: February 04, 2019 (last updated November 27, 2024)
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
0
Attacker Value
Unknown
CVE-2018-10893
Disclosure Date: September 11, 2018 (last updated November 27, 2024)
Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cause the client to crash or, potentially, execute arbitrary code.
0
Attacker Value
Unknown
CVE-2018-10873
Disclosure Date: August 17, 2018 (last updated November 27, 2024)
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
0
Attacker Value
Unknown
CVE-2016-9578
Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
0
Attacker Value
Unknown
CVE-2016-9577
Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
0
Attacker Value
Unknown
CVE-2017-12194
Disclosure Date: March 14, 2018 (last updated November 26, 2024)
A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of malicious spice-server, could use this flaw to crash the client or execute arbitrary code with permissions of the user running the client. spice-gtk versions through 0.34 are believed to be vulnerable.
0
Attacker Value
Unknown
CVE-2017-15108
Disclosure Date: January 20, 2018 (last updated November 26, 2024)
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary commands to be executed.
0
Attacker Value
Unknown
CVE-2017-7506
Disclosure Date: July 18, 2017 (last updated November 26, 2024)
spice versions though 0.13 are vulnerable to out-of-bounds memory access when processing specially crafted messages from authenticated attacker to the spice server resulting into crash and/or server memory leak.
0