Page 2 of 12244 results (0.002 seconds)

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-73: External Control of File Name or Path •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than a folder that only users with administrative privilege have permission to modify. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-276: Incorrect Default Permissions •

CVSS: 4.6EPSS: 0%CPEs: -EXPL: 0

IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials. • https://www.ibm.com/support/pages/node/6608458 • CWE-522: Insufficiently Protected Credentials •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

IBM Cognos Analytics Mobile for Android 1.1.14 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. • https://www.ibm.com/support/pages/node/6555140 • CWE-319: Cleartext Transmission of Sensitive Information

CVSS: 5.5EPSS: 0%CPEs: -EXPL: 0

This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. •