Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-44487

Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Attacker Value
Unknown

CVE-2020-1472

Disclosure Date: August 17, 2020 (last updated February 21, 2025)
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers…
1
Attacker Value
Unknown

CVE-2025-0145

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Untrusted search path in the installer for some Zoom Workplace Apps for Windows may allow an authorized user to conduct an escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2024-54540

Disclosure Date: January 15, 2025 (last updated January 16, 2025)
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
0
Attacker Value
Unknown

CVE-2024-49105

Disclosure Date: December 12, 2024 (last updated January 13, 2025)
Remote Desktop Client Remote Code Execution Vulnerability
0
Attacker Value
Unknown

CVE-2024-50307

Disclosure Date: October 28, 2024 (last updated October 28, 2024)
Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows) versions prior to 2.9.2. If a user clicks a specially crafted link in the application, an arbitrary file may be downloaded from an external website and executed. As a result, arbitrary code may be executed on the device that runs Chatwork Desktop Application (Windows).
0
Attacker Value
Unknown

CVE-2024-39827

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper input validation in the installer for Zoom Workplace Desktop App for Windows before version 6.0.10 may allow an authenticated user to conduct a denial of service via local access.
0
Attacker Value
Unknown

CVE-2024-39821

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Race condition in the installer for Zoom Workplace App for Windows and Zoom Rooms App for Windows may allow an authenticated user to conduct a denial of service via local access.
0
Attacker Value
Unknown

CVE-2024-39819

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper privilege management in the installer for some Zoom Workplace Apps and SDKs for Windows may allow an authenticated user to conduct a privilege escalation via local access.
0
Attacker Value
Unknown

CVE-2024-27240

Disclosure Date: July 15, 2024 (last updated July 16, 2024)
Improper input validation in the installer for some Zoom Apps for Windows may allow an authenticated user to conduct a privilege escalation via local access.
0