Show filters
3,556 Total Results
Displaying 91-100 of 3,556
Sort by:
Attacker Value
Unknown
CVE-2024-11671
Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
0
Attacker Value
Unknown
CVE-2024-11670
Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
0
Attacker Value
Unknown
CVE-2024-50307
Disclosure Date: October 28, 2024 (last updated October 28, 2024)
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).
0
Attacker Value
Unknown
CVE-2024-9348
Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
0
Attacker Value
Unknown
CVE-2024-22034
Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
0
Attacker Value
Unknown
CVE-2024-47771
Disclosure Date: October 15, 2024 (last updated October 16, 2024)
Element Desktop is a Matrix client for desktop platforms. Element Desktop versions 1.11.70 through 1.11.80 contain a vulnerability which can, under specially crafted conditions, lead to the access token becoming exposed to third parties. At least one vector has been identified internally, involving malicious widgets, but other vectors may exist. Users are strongly advised to upgrade to version 1.11.81 to remediate the issue. As a workaround, avoid granting permissions to untrusted widgets.
0
Attacker Value
Unknown
CVE-2024-7421
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain session credentials via passwords included in command-line arguments when launching WinSCP sessions
0
Attacker Value
Unknown
CVE-2024-45835
Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather Chromium cookies or abuse other misconfigurations via remote/local access.
0
Attacker Value
Unknown
CVE-2024-39772
Disclosure Date: September 16, 2024 (last updated November 02, 2024)
Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.
0
Attacker Value
Unknown
CVE-2024-39613
Disclosure Date: September 16, 2024 (last updated September 21, 2024)
Mattermost Desktop App versions <=5.8.0 fail to specify an absolute path when searching the cmd.exe file, which allows a local attacker who is able to put an cmd.exe file in the Downloads folder of a user's machine to cause remote code execution on that machine.
0