Show filters
998 Total Results
Displaying 51-60 of 998
Sort by:
Attacker Value
Unknown

CVE-2023-39309

Disclosure Date: March 28, 2024 (last updated April 02, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
0
Attacker Value
Unknown

CVE-2023-39311

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in ThemeFusion Fusion Builder.This issue affects Fusion Builder: from n/a through 3.11.1.
0
Attacker Value
Unknown

CVE-2023-39306

Disclosure Date: March 27, 2024 (last updated April 02, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeFusion Fusion Builder allows Reflected XSS.This issue affects Fusion Builder: from n/a through 3.11.1.
0
Attacker Value
Unknown

CVE-2024-22255

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability in the UHCI USB controller. A malicious actor with administrative access to a virtual machine may be able to exploit this issue to leak memory from the vmx process.  
0
Attacker Value
Unknown

CVE-2024-22253

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the UHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown

CVE-2024-22252

Disclosure Date: March 05, 2024 (last updated March 06, 2024)
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.
0
Attacker Value
Unknown

CVE-2024-22251

Disclosure Date: February 29, 2024 (last updated February 29, 2024)
VMware Workstation and Fusion contain an out-of-bounds read vulnerability in the USB CCID (chip card interface device). A malicious actor with local administrative privileges on a virtual machine may trigger an out-of-bounds read leading to information disclosure.
0
Attacker Value
Unknown

CVE-2024-23387

Disclosure Date: January 19, 2024 (last updated January 25, 2024)
FusionPBX prior to 5.1.0 contains a cross-site scripting vulnerability. If this vulnerability is exploited by a remote authenticated attacker with an administrative privilege, an arbitrary script may be executed on the web browser of the user who is logging in to the product.
Attacker Value
Unknown

CVE-2023-51751

Disclosure Date: January 11, 2024 (last updated January 23, 2024)
ScaleFusion 10.5.2 does not properly limit users to the Edge application because Alt-F4 can be used. This is fixed in 10.5.7 by preventing the launching of the file explorer in Agent-based Multi-App and Single App Kiosk mode.
Attacker Value
Unknown

CVE-2023-51750

Disclosure Date: January 11, 2024 (last updated January 23, 2024)
ScaleFusion 10.5.2 does not properly limit users to the Edge application because file downloads can occur. NOTE: the vendor's position is "Not vulnerable if the default Windows device profile configuration is used which utilizes modern management with website allow-listing rules."