Show filters
109 Total Results
Displaying 1-10 of 109
Sort by:
Attacker Value
Unknown

CVE-2025-0500

Disclosure Date: January 15, 2025 (last updated January 29, 2025)
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
0
Attacker Value
Unknown

CVE-2023-43078

Disclosure Date: August 28, 2024 (last updated December 20, 2024)
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
Attacker Value
Unknown

CVE-2024-0056

Disclosure Date: January 09, 2024 (last updated January 12, 2025)
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-41138

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.
Attacker Value
Unknown

CVE-2023-41137

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.
Attacker Value
Unknown

CVE-2023-32476

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
Dell Hybrid Client version 2.0 contains a Sensitive Data Exposure vulnerability. An unauthenticated malicious user on the device can access hard coded secrets in javascript files.
Attacker Value
Unknown

CVE-2022-34858

Disclosure Date: August 02, 2022 (last updated February 24, 2025)
Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.
Attacker Value
Unknown

CVE-2021-27783

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Attacker Value
Unknown

CVE-2022-25166

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.
Attacker Value
Unknown

CVE-2022-25165

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows parameters outside of the AWS VPN Client allow list to be injected into the configuration file prior to the AWS VPN Client service (running as SYSTEM) processing the file. Dangerous arguments can be injected by a low-level user such as log, which allows an arbitrary destination to be specified for writing log files. This leads to an arbitrary file write as SYSTEM with partial control over the files content. This can be abused to cause an elevation of privilege or denial of service.