Lucene search

K

Client Security Vulnerabilities

cve
cve

CVE-2021-27893

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is...

7CVSS

6.9AI Score

0.0004EPSS

2021-03-15 03:15 PM
27
cve
cve

CVE-2021-27892

SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is...

7.8CVSS

7.4AI Score

0.0004EPSS

2021-03-15 03:15 PM
18
4
cve
cve

CVE-2021-27891

SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is...

8.8CVSS

8.4AI Score

0.001EPSS

2021-03-15 03:15 PM
29
4
cve
cve

CVE-2021-21518

Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-03-12 08:15 PM
39
2
cve
cve

CVE-2021-20674

Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified directory and to execute arbitrary code with the privilege of the user invoking the installer when a...

7.8CVSS

8.1AI Score

0.001EPSS

2021-03-12 02:15 AM
55
2
cve
cve

CVE-2020-36282

JMS Client for RabbitMQ 1.x before 1.15.2 and 2.x before 2.2.0 is vulnerable to unsafe deserialization that can result in code execution via crafted StreamMessage...

9.8CVSS

9.6AI Score

0.004EPSS

2021-03-12 01:15 AM
67
5
cve
cve

CVE-2021-21331

The Java client for the Datadog API before version 1.0.0-beta.9 has a local information disclosure of sensitive information downloaded via the API using the API Client. The Datadog API is executed on a unix-like system with multiple users. The API is used to download a file containing sensitive...

3.3CVSS

3.7AI Score

0.001EPSS

2021-03-03 11:15 PM
54
2
cve
cve

CVE-2021-25329

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the...

7CVSS

7.1AI Score

0.922EPSS

2021-03-01 12:15 PM
528
27
cve
cve

CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's...

7.5CVSS

6.7AI Score

0.002EPSS

2021-03-01 12:15 PM
585
15
cve
cve

CVE-2020-28646

ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were...

7.8CVSS

7.6AI Score

0.001EPSS

2021-02-26 03:15 PM
55
2
cve
cve

CVE-2021-20327

A specific version of the Node.js mongodb-client-encryption module does not perform correct validation of the KMS server’s certificate. This vulnerability in combination with a privileged network position active MITM attack could result in interception of traffic between the Node.js driver and the....

6.8CVSS

6.4AI Score

0.0005EPSS

2021-02-25 05:15 PM
35
4
cve
cve

CVE-2021-1450

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid...

5.5CVSS

5.3AI Score

0.0004EPSS

2021-02-24 08:15 PM
29
3
cve
cve

CVE-2021-1366

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client....

7.8CVSS

7.6AI Score

0.0004EPSS

2021-02-17 05:15 PM
419
12
cve
cve

CVE-2020-11635

The Zscaler Client Connector prior to 3.1.0 did not sufficiently validate RPC clients, which allows a local adversary to execute code with system privileges or perform limited actions for which they did not have...

7.8CVSS

7.7AI Score

0.0004EPSS

2021-02-16 08:15 PM
29
cve
cve

CVE-2021-22980

In Edge Client version 7.2.x before 7.2.1.1, 7.1.9.x before 7.1.9.8, and 7.1.x-7.1.8.x before 7.1.8.5, an untrusted search path vulnerability in the BIG-IP APM Client Troubleshooting Utility (CTU) for Windows could allow an attacker to load a malicious DLL library from its current directory. User.....

7.8CVSS

7.4AI Score

0.001EPSS

2021-02-12 06:15 PM
59
cve
cve

CVE-2021-27188

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 allows attackers to cause a denial of service (access suspended for five hours) by making five invalid login attempts to a victim's...

7.5CVSS

7.3AI Score

0.001EPSS

2021-02-12 08:15 AM
22
cve
cve

CVE-2021-27187

The Sovremennye Delovye Tekhnologii FX Aggregator terminal client 1 stores authentication credentials in cleartext in login.sav when the Save Password box is...

7.5CVSS

7.6AI Score

0.001EPSS

2021-02-12 08:15 AM
23
3
cve
cve

CVE-2021-25689

An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remotely execute...

9.8CVSS

9.4AI Score

0.004EPSS

2021-02-11 06:15 PM
20
3
cve
cve

CVE-2021-25690

A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the...

7.5CVSS

7.4AI Score

0.001EPSS

2021-02-11 06:15 PM
15
3
cve
cve

CVE-2021-27185

The samba-client package before 4.0.0 for Node.js allows command injection because of the use of...

9.8CVSS

9.7AI Score

0.005EPSS

2021-02-10 10:15 PM
48
3
cve
cve

CVE-2020-8570

Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process...

9.1CVSS

8.2AI Score

0.004EPSS

2021-01-21 05:15 PM
67
7
cve
cve

CVE-2021-3183

Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login...

7.5CVSS

7.7AI Score

0.002EPSS

2021-01-19 03:15 PM
19
2
cve
cve

CVE-2021-1258

A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission...

5.5CVSS

5.3AI Score

0.0004EPSS

2021-01-13 10:15 PM
53
cve
cve

CVE-2021-1237

A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on....

7.8CVSS

7.8AI Score

0.0004EPSS

2021-01-13 10:15 PM
92
3
cve
cve

CVE-2021-20616

Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified...

7.8CVSS

7.7AI Score

0.001EPSS

2021-01-13 10:15 AM
23
9
cve
cve

CVE-2020-27644

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges by placing a malicious cryptbase.dll file in...

8.8CVSS

8.2AI Score

0.002EPSS

2020-12-29 09:15 PM
31
3
cve
cve

CVE-2020-27643

The %PROGRAMDATA%\1E\Client directory in 1E Client 5.0.0.745 and 4.1.0.267 allows remote authenticated users and local users to create and modify files in protected directories (where they would not normally have access to create or modify files) via the creation of a junction point to a system...

6.5CVSS

6.1AI Score

0.001EPSS

2020-12-29 09:15 PM
25
3
cve
cve

CVE-2020-27645

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated...

8.8CVSS

8.2AI Score

0.002EPSS

2020-12-29 09:15 PM
30
3
cve
cve

CVE-2020-16268

The MSI installer in 1E Client 4.1.0.267 and 5.0.0.745 allows remote authenticated users and local users to gain elevated privileges via the repair option. This applies to installations that have a TRANSFORM (MST) with the option to disable the installation of the Nomad module. An attacker may...

8.8CVSS

8.2AI Score

0.002EPSS

2020-12-29 09:15 PM
30
3
cve
cve

CVE-2020-14231

A vulnerability in the input parameter handling of HCL Client Application Access v9 could potentially be exploited by an authenticated attacker resulting in a stack buffer overflow. This could allow the attacker to crash the program or inject code into the system which would execute with the...

8.8CVSS

8.6AI Score

0.001EPSS

2020-12-22 08:15 PM
28
cve
cve

CVE-2020-7838

A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client...

8.8CVSS

8.8AI Score

0.003EPSS

2020-12-18 01:15 AM
45
2
cve
cve

CVE-2020-5798

inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user from a lower privileged user due to improper integrity checks and directory...

7.8CVSS

7.5AI Score

0.001EPSS

2020-12-07 01:15 PM
119
cve
cve

CVE-2020-6021

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted.....

7.8CVSS

7.5AI Score

0.0004EPSS

2020-12-03 02:15 PM
30
cve
cve

CVE-2020-25989

Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root...

7.8CVSS

8AI Score

0.0005EPSS

2020-11-19 09:15 PM
20
cve
cve

CVE-2020-9049

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid...

7.1CVSS

5.5AI Score

0.001EPSS

2020-11-19 04:15 PM
36
cve
cve

CVE-2020-12331

Improper access controls in Intel Unite(R) Cloud Service client before version 4.2.12212 may allow an authenticated user to potentially enable escalation of privilege via local...

7.8CVSS

7.7AI Score

0.0004EPSS

2020-11-12 07:15 PM
30
cve
cve

CVE-2020-12311

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical...

4.6CVSS

5AI Score

0.001EPSS

2020-11-12 06:15 PM
37
cve
cve

CVE-2020-12310

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical...

4.6CVSS

5AI Score

0.001EPSS

2020-11-12 06:15 PM
30
cve
cve

CVE-2020-12309

Insufficiently protected credentialsin subsystem in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical...

4.6CVSS

5AI Score

0.001EPSS

2020-11-12 06:15 PM
32
cve
cve

CVE-2020-0575

Improper buffer restrictions in the Intel(R) Unite Client for Windows* before version 4.2.13064 may allow an authenticated user to potentially enable information disclosure via local...

5.5CVSS

5.2AI Score

0.0004EPSS

2020-11-12 06:15 PM
23
cve
cve

CVE-2020-26807

SAP ERP Client for E-Bilanz, version - 1.0, installation sets Incorrect default filesystem permissions are set in its installation folder which allows anyone to modify the files in the...

3.3CVSS

4.2AI Score

0.0004EPSS

2020-11-10 05:15 PM
20
cve
cve

CVE-2020-3556

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC...

7.3CVSS

7.1AI Score

0.0004EPSS

2020-11-06 07:15 PM
170
4
cve
cve

CVE-2020-27123

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function.....

5.5CVSS

5.3AI Score

0.0004EPSS

2020-11-06 07:15 PM
48
cve
cve

CVE-2020-6014

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point.....

6.5CVSS

6.9AI Score

0.0004EPSS

2020-11-02 09:15 PM
21
cve
cve

CVE-2020-15914

A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target...

5.4CVSS

5.4AI Score

0.001EPSS

2020-11-02 09:15 PM
20
cve
cve

CVE-2020-8260

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip...

7.2CVSS

8.2AI Score

0.025EPSS

2020-10-28 01:15 PM
971
In Wild
21
cve
cve

CVE-2020-8263

A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) through the CGI...

5.4CVSS

5AI Score

0.001EPSS

2020-10-28 01:15 PM
29
cve
cve

CVE-2020-8240

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the...

7.8CVSS

7.4AI Score

0.0004EPSS

2020-10-28 01:15 PM
33
cve
cve

CVE-2020-8248

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate...

7.8CVSS

7.4AI Score

0.0004EPSS

2020-10-28 01:15 PM
17
cve
cve

CVE-2020-8255

A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary file reading vulnerability is fixed using encrypted URL blacklisting that prevents these...

4.9CVSS

4.9AI Score

0.001EPSS

2020-10-28 01:15 PM
36
Total number of security vulnerabilities1374