Show filters
280 Total Results
Displaying 51-60 of 280
Sort by:
Attacker Value
Unknown
CVE-2024-7202
Disclosure Date: July 29, 2024 (last updated September 11, 2024)
The query functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
0
Attacker Value
Unknown
CVE-2024-7201
Disclosure Date: July 29, 2024 (last updated September 11, 2024)
The login functionality of WinMatrix3 Web package from Simopro Technology lacks proper validation of user input, allowing unauthenticated remote attackers to inject SQL commands to read, modify, and delete database contents.
0
Attacker Value
Unknown
CVE-2024-40648
Disclosure Date: July 18, 2024 (last updated July 19, 2024)
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. The `UserIdentity::is_verified()` method in the matrix-sdk-crypto crate before version 0.7.2 doesn't take into account the verification status of the user's own identity while performing the check and may as a result return a value contrary to what is implied by its name and documentation. If the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the `matrix-sdk-crypto` crate. The 0.7.2 release of the `matrix-sdk-crypto` crate includes a fix. All users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-6286
Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
0
Attacker Value
Unknown
CVE-2024-6150
Disclosure Date: July 10, 2024 (last updated July 11, 2024)
A non-admin user can cause short-term disruption in Target VM availability in Citrix Provisioning
0
Attacker Value
Unknown
CVE-2024-6149
Disclosure Date: July 10, 2024 (last updated July 11, 2024)
Redirection of users to a vulnerable URL in Citrix Workspace app for HTML5
0
Attacker Value
Unknown
CVE-2024-39691
Disclosure Date: July 05, 2024 (last updated July 06, 2024)
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The fix for GHSA-wm4w-7h2q-3pf7 / CVE-2024-32000 included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether or not to include a truncated version of the original event in the IRC message. Since this value is controlled by external entities, a malicious Matrix homeserver joined to a room in which a matrix-appservice-irc bridge instance (before version 2.0.1) is present can fabricate the timestamp with the intent of tricking the bridge into leaking room messages the homeserver should not have access to. matrix-appservice-irc 2.0.1 drops the reliance on `origin_server_ts` when determining whether or not an event should be visible to a user, instead tracking the event timestamps internally. As a workaround, it's possible to limit the amount of information leaked by setting a reply t…
0
Attacker Value
Unknown
CVE-2024-6298
Disclosure Date: July 05, 2024 (last updated December 05, 2024)
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to execute arbitrary code remotely
0
Attacker Value
Unknown
CVE-2024-6209
Disclosure Date: July 05, 2024 (last updated December 05, 2024)
Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series
v3.08.01
; MATRIX Series
v3.08.01 allows Attacker to access files unauthorized
0
Attacker Value
Unknown
CVE-2024-4007
Disclosure Date: July 01, 2024 (last updated July 02, 2024)
Default credential in install package in ABB ASPECT; NEXUS Series; MATRIX Series version 3.07 allows attacker to login to product instances wrongly configured.
0