
CVE-2021-42976
https://notcve.org/view.php?id=CVE-2021-42976
07 Dec 2021 — NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. NoMachine Enterprise Desktop está afectado por un Desbordamiento del Búfer. IOCTL Handler 0x22001B en NoMachine Enterprise Desktop versiones posteriores de 4.0.346 y anteriores a 7.7.4, permite a... • https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2021-42973
https://notcve.org/view.php?id=CVE-2021-42973
07 Dec 2021 — NoMachine Server is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. NoMachine Server está afectado por un desbordamiento de enteros. IOCTL Handler 0x22001B en NoMachine Server versiones posteriores de 4.0.346 y anteriores a 7.7.4, permite a atacantes locales ejecutar código arbitrario ... • https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services • CWE-190: Integer Overflow or Wraparound •

CVE-2021-42972
https://notcve.org/view.php?id=CVE-2021-42972
07 Dec 2021 — NoMachine Server is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Server above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. NoMachine Server está afectado por el Desbordamiento del Búfer. IOCTL Handler 0x22001B en NoMachine Server versiones posteriores de 4.0.346 y anteriores a 7.7.4, permite a atacantes locales ejecutar código arbitrario en... • https://www.sentinelone.com/labs/usb-over-ethernet-multiple-privilege-escalation-vulnerabilities-in-aws-and-other-major-cloud-services • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2018-20029
https://notcve.org/view.php?id=CVE-2018-20029
10 Dec 2018 — The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachine before 6.4.6 on Windows 10 allows local users to cause a denial of service (BSOD) because uninitialized memory can be read. El controlador nxfs.sys en la biblioteca DokanFS 0.6.0 en NoMachine en versiones anteriores a la 6.4.6 en Windows 10 permite que los usuarios locales provoquen una denegación de servicio (BSOD) debido a que se puede leer la memoria no inicializada. • https://www.nomachine.com/TR11P08975 • CWE-908: Use of Uninitialized Resource •

CVE-2018-17980 – NoMachine < 5.3.27 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2018-17980
12 Oct 2018 — NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan horse code is executed. (The directory could, in general, be on a local filesystem or a network share.). NoMachine en versiones anteriores a la 5.3.27 y versiones 6.x anteriores a la 6.3.6 permite que los atacantes obtengan privilegi... • https://packetstorm.news/files/id/149784 • CWE-426: Untrusted Search Path •

CVE-2018-0664
https://notcve.org/view.php?id=CVE-2018-0664
04 Sep 2018 — A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors. Una vulnerabilidad en NoMachine App para Android 5.0.63 y anteriores permite que los atacantes alteren las variables de entorno mediante vectores sin especificar. • http://jvn.jp/en/jp/JVN14451678/index.html • CWE-20: Improper Input Validation •

CVE-2018-6947 – NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation
https://notcve.org/view.php?id=CVE-2018-6947
23 Feb 2018 — An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier allows a local low privileged user to gain elevation of privileges on Windows 7 (32 and 64bit), and denial of service for Windows 8 and 10. Una variable de pila no inicializada en el componente nxfuse de la biblioteca Open Source DokanFS incluida en NoMachine, en versiones 6.0.66_2 y anteriores, permite que un usuario local con pocos privilegios eleve sus privil... • https://packetstorm.news/files/id/146544 • CWE-665: Improper Initialization •

CVE-2017-12763 – NoMachine 5.3.9 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2017-12763
29 Aug 2017 — An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files. Una utilidad del servidor sin especificar en NoMachine en versiones anteriores a la 5.3.10 en Mac OS X y Linux permite que usuarios autenticados obtengan privilegios obteniendo acceso a archivos locales. • https://www.exploit-db.com/exploits/42460 • CWE-276: Incorrect Default Permissions •

CVE-2012-5003
https://notcve.org/view.php?id=CVE-2012-5003
19 Sep 2012 — nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file. nxapplet.jar en No Machine NX Web Companion 3.x y anteriores no verifican de forma adecuada la autenticidad de actualizaciones, o que permite a atacantes remotos asistidos por usuarios locales a ejecutar código mediante... • http://archives.neohapsis.com/archives/bugtraq/2012-01/0161.html • CWE-287: Improper Authentication •

CVE-2011-3977
https://notcve.org/view.php?id=CVE-2011-3977
04 Oct 2011 — Unspecified vulnerability in nxconfigure.sh in NoMachine NX Node 3.x before 3.5.0-4 and NX Server 3.x before 3.5.0-5 allows local users to read arbitrary files via unknown vectors. Vulnerabilidad no especificada en nxconfigure.sh en NoMachine NX Nodo v3.x anterior a v3.5.0-4 y NX Server v3.x anterior a v3.5.0-5 permite a usuarios locales leer ficheros arbitrarios a través de vectores desconocidos. • http://securityreason.com/securityalert/8406 •