|
312481
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML…
|
NVD-CWE-noinfo
|
CVE-2024-7001
|
2024-08-8 06:33 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312482
|
7.5 |
HIGH
Network
|
zscaler
|
client_connector
|
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-23456
|
2024-08-8 06:30 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312483
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-23460
|
2024-08-8 06:29 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312484
|
7.8 |
HIGH
Local
|
zscaler
|
client_connector
|
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscale…
|
CWE-346
Origin Validation Error
|
CVE-2024-23458
|
2024-08-8 06:29 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312485
|
6.5 |
MEDIUM
Network
|
zscaler
|
client_connector
|
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2023-28806
|
2024-08-8 06:29 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312486
|
8.8 |
HIGH
Network
|
datagear
|
datagear
|
A vulnerability was found in DataGear up to 5.0.0. It has been declared as critical. Affected by this vulnerability is the function evaluateVariableExpression of the file ConversionSqlParamValueMappe…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2024-7552
|
2024-08-8 06:29 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312487
|
9.8 |
CRITICAL
Network
|
zscaler
|
client_connector
|
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.
|
CWE-78
OS Command
|
CVE-2024-23483
|
2024-08-8 06:23 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312488
|
4.9 |
MEDIUM
Network
|
zscaler
|
client_connector
|
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
|
NVD-CWE-noinfo
|
CVE-2024-23464
|
2024-08-8 06:23 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312489
|
9.8 |
CRITICAL
Network
|
vivotek
|
cc8160_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d. It has been classified as critical. This affects the function getenv of the file upload_file.cgi. The manipulat…
|
CWE-77
Command Injection
|
CVE-2024-7440
|
2024-08-8 06:15 |
2024-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312490
|
- |
|
novell
|
groupwise groupwise_webaccess
|
NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as…
|
NVD-CWE-Other
|
CVE-2005-0296
|
2024-08-8 06:15 |
2005-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|