Lucene search

K

Client Security Vulnerabilities

cve
cve

CVE-2020-8968

Parallels Remote Application Server (RAS) allows a local attacker to retrieve certain profile password in clear text format by uploading a previously stored cyphered file by Parallels RAS. The confidentiality, availability and integrity of the information of the user could be compromised if an...

7.1CVSS

6.7AI Score

0.0004EPSS

2021-12-17 05:15 PM
27
cve
cve

CVE-2021-34425

The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side request forgery vulnerability in the chat's "link preview" functionality. In versions prior to 5.7.3, if a user were to enable the chat's "link preview" feature, a malicio...

6.1CVSS

6.3AI Score

0.001EPSS

2021-12-14 08:15 PM
35
cve
cve

CVE-2021-34426

A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase git lfs-config" command on the command-line. In versions prior to 5.6.0, a malicious actor with write access to a user's Git repository could leverage this vulnerability to.....

7.8CVSS

7.9AI Score

0.0004EPSS

2021-12-14 08:15 PM
30
cve
cve

CVE-2021-34409

It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) installation before version 5.2.0, Zoom Client Plugin for Sharing iPhone/iPad before version 5.2.0, and Zoom Rooms for Conference before version 5.1.0, copy pre- and post-...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-12-14 12:00 AM
25
4
cve
cve

CVE-2021-39048

IBM Spectrum Protect Client 7.1 and 8.1 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID:...

5.5CVSS

5.6AI Score

0.0004EPSS

2021-12-13 07:15 PM
22
cve
cve

CVE-2021-20047

SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target...

7.8CVSS

7.8AI Score

0.001EPSS

2021-12-08 10:15 AM
29
4
cve
cve

CVE-2021-42688

An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS....

8.8CVSS

8.8AI Score

0.0004EPSS

2021-12-07 09:15 PM
21
2
cve
cve

CVE-2021-42687

A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request...

8.8CVSS

8.7AI Score

0.0004EPSS

2021-12-07 09:15 PM
19
2
cve
cve

CVE-2021-42683

A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request...

8.8CVSS

8.7AI Score

0.0004EPSS

2021-12-07 09:15 PM
15
4
cve
cve

CVE-2021-42686

An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Accops HyWorks Windows Client prior to v 3.2.8.200 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via...

8.8CVSS

8.8AI Score

0.0004EPSS

2021-12-07 09:15 PM
15
2
cve
cve

CVE-2021-42983

NoMachine Enterprise Client is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O....

8.8CVSS

8.8AI Score

0.0004EPSS

2021-12-07 08:15 PM
17
cve
cve

CVE-2021-42986

NoMachine Enterprise Client is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted...

8.8CVSS

8.7AI Score

0.0004EPSS

2021-12-07 08:15 PM
13
cve
cve

CVE-2021-42711

Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This file is executed with SYSTEM privileges when an unprivileged user performs a repair...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-12-01 11:15 PM
20
2
cve
cve

CVE-2021-34424

A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before version 5.8.4,...

7.5CVSS

8AI Score

0.002EPSS

2021-11-24 05:15 PM
125
2
cve
cve

CVE-2021-34423

A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.8.4, Zoom Client for Meetings for Blackberry (for Android and iOS) before version 5.8.1, Zoom Client for Meetings for intune (for Android and iOS) before...

9.8CVSS

9.2AI Score

0.004EPSS

2021-11-24 05:15 PM
166
3
cve
cve

CVE-2021-39198

OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a vulnerability which could an attacker is able to disqualify any Lead with a Cross-Site Request Forgery (CSRF) attack. There are no workarounds that address this vulnerability and.....

5.4CVSS

5.5AI Score

0.001EPSS

2021-11-19 10:15 PM
41
cve
cve

CVE-2021-23155

Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Client for Android 8.60 versions prior to 8.60.065; version 8.50 and prior...

9CVSS

6.5AI Score

0.001EPSS

2021-11-18 06:15 PM
17
cve
cve

CVE-2021-24787

The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is...

4.8CVSS

4.7AI Score

0.001EPSS

2021-11-17 11:15 AM
20
cve
cve

CVE-2021-34421

The Keybase Client for Android before version 5.8.0 and the Keybase Client for iOS before version 5.8.0 fails to properly remove exploded messages initiated by a user if the receiving user places the chat session in the background while the sending user explodes the messages. This could lead to...

4.3CVSS

4AI Score

0.001EPSS

2021-11-12 12:00 AM
27
2
cve
cve

CVE-2021-34420

The Zoom Client for Meetings for Windows installer before version 5.5.4 does not properly verify the signature of files with .msi, .ps1, and .bat extensions. This could lead to a malicious actor installing malicious software on a customer’s...

7.4CVSS

7.3AI Score

0.001EPSS

2021-11-12 12:00 AM
77
cve
cve

CVE-2021-34419

In the Zoom Client for Meetings for Ubuntu Linux before version 5.1.0, there is an HTML injection flaw when sending a remote control request to a user in the process of in-meeting screen sharing. This could allow meeting participants to be targeted for social engineering...

5.3CVSS

5.3AI Score

0.001EPSS

2021-11-12 12:00 AM
25
cve
cve

CVE-2021-34422

The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a file uploaded to a team folder. A malicious user could upload a file to a shared folder with a specially crafted file name which could allow a user to execute an application...

9CVSS

9.4AI Score

0.004EPSS

2021-11-12 12:00 AM
23
cve
cve

CVE-2021-38666

Remote Desktop Client Remote Code Execution...

8.8CVSS

9AI Score

0.053EPSS

2021-11-10 01:18 AM
116
cve
cve

CVE-2021-38665

Remote Desktop Protocol Client Information Disclosure...

7.4CVSS

7AI Score

0.013EPSS

2021-11-10 01:18 AM
79
2
cve
cve

CVE-2021-40124

A vulnerability in the Network Access Manager (NAM) module of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to escalate privileges on an affected device. This vulnerability is due to incorrect privilege assignment to scripts executed before user...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-11-04 04:15 PM
2141
cve
cve

CVE-2021-41036

In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in...

9.8CVSS

9.3AI Score

0.001EPSS

2021-11-03 12:15 AM
32
cve
cve

CVE-2021-29644

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 contains a remote code execution vulnerability because of an Integer Overflow. An attacker with network access to port 31016 may exploit this issue to execute code with unrestricted privileges on the underlying...

9.8CVSS

9.7AI Score

0.006EPSS

2021-10-12 07:15 PM
28
cve
cve

CVE-2021-29645

Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-10-12 07:15 PM
22
cve
cve

CVE-2021-25738

Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code...

6.7CVSS

6.8AI Score

0.0004EPSS

2021-10-11 07:15 PM
70
4
cve
cve

CVE-2021-34788

A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the...

7CVSS

7AI Score

0.0004EPSS

2021-10-06 08:15 PM
27
cve
cve

CVE-2021-36286

Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object...

7.1CVSS

6.9AI Score

0.0004EPSS

2021-09-28 08:15 PM
29
cve
cve

CVE-2021-36297

SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing...

7.8CVSS

7.6AI Score

0.001EPSS

2021-09-28 08:15 PM
23
cve
cve

CVE-2021-34408

The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable directory as a privileged user during the installation or update of the client. This could allow for potential privilege escalation if a link was created between the user writable...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-09-27 02:15 PM
28
cve
cve

CVE-2021-33907

The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate information used to sign .msi files when performing an update of the client. This could lead to remote code execution in an elevated privileged...

9.8CVSS

9.5AI Score

0.004EPSS

2021-09-27 02:15 PM
28
cve
cve

CVE-2021-34412

During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possible to launch Internet Explorer. If the installer was launched with elevated privileges such as by SCCM this can result in a local privilege...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-09-27 02:15 PM
28
cve
cve

CVE-2021-41011

LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this...

7.5CVSS

7.1AI Score

0.002EPSS

2021-09-22 03:15 PM
21
cve
cve

CVE-2021-20037

SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This vulnerability impacts GVC 4.10.5 installer and...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-09-21 09:15 AM
16
cve
cve

CVE-2021-35493

The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker....

9CVSS

5.8AI Score

0.001EPSS

2021-09-14 06:15 PM
26
cve
cve

CVE-2021-38150

When an attacker manages to get access to the local memory, or the memory dump of a victim, for example by a social engineering attack, SAP Business Client versions - 7.0, 7.70, will allow him to read extremely sensitive data, such as credentials. This would allow the attacker to compromise the...

6.5CVSS

6.2AI Score

0.002EPSS

2021-09-14 12:15 PM
22
cve
cve

CVE-2021-36215

LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address...

5.3CVSS

5AI Score

0.001EPSS

2021-09-08 06:15 PM
48
cve
cve

CVE-2021-31338

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.0 SP1). Affected devices allow to modify configuration settings over an unauthenticated channel. This could allow a local attacker to escalate privileges and execute own code on the...

7.8CVSS

7.8AI Score

0.0004EPSS

2021-08-19 04:15 PM
48
2
cve
cve

CVE-2021-21598

Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log...

3.9CVSS

3.8AI Score

0.0004EPSS

2021-08-10 07:15 PM
20
cve
cve

CVE-2021-21597

Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log...

7.2CVSS

3.6AI Score

0.0004EPSS

2021-08-10 07:15 PM
20
cve
cve

CVE-2021-33699

Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in their AndroidManifest.xml with their Task Control features. This allows an unauthorized attacker or malware to takeover legitimate apps and to steal user's sensitive...

6.5CVSS

6.3AI Score

0.001EPSS

2021-08-10 03:15 PM
23
cve
cve

CVE-2021-33597

A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the...

5.5CVSS

5.5AI Score

0.001EPSS

2021-08-05 08:15 PM
18
5
cve
cve

CVE-2020-5316

Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-07-22 05:15 PM
23
6
cve
cve

CVE-2021-2351

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option......

8.3CVSS

8.5AI Score

0.013EPSS

2021-07-21 03:15 PM
157
9
cve
cve

CVE-2021-25701

The fUSBHub driver in the PCoIP Software Client prior to version 21.07.0 had an error in object management during the handling of a variety of IOCTLs, which allowed an attacker to cause a denial of...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-07-21 03:15 PM
19
4
cve
cve

CVE-2021-25698

The OpenSSL component of the Teradici PCoIP Standard Agent prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration...

7.8CVSS

7.4AI Score

0.001EPSS

2021-07-21 03:15 PM
18
5
cve
cve

CVE-2021-25699

The OpenSSL component of the Teradici PCoIP Software Client prior to version 21.07.0 was compiled without the no-autoload-config option, which allowed an attacker to elevate to the privileges of the running process via placing a specially crafted dll in a build configuration...

7.8CVSS

7.4AI Score

0.001EPSS

2021-07-21 03:15 PM
16
4
Total number of security vulnerabilities1374