6 results (0.002 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

30 May 2025 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a COM hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120745 • CWE-427: Uncontrolled Search Path Element •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

30 May 2025 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120744 • CWE-427: Uncontrolled Search Path Element •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Apr 2025 — HCL Traveler is affected by an internal path disclosure in a Windows application when the application inadvertently reveals internal file paths, in error messages, debug logs, or responses to user requests. HCL Traveler se ve afectado por una divulgación de ruta interna en una aplicación de Windows cuando la aplicación revela inadvertidamente rutas de archivos internas, en mensajes de error, registros de depuración o respuestas a solicitudes de usuario. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120335 • CWE-497: Exposure of Sensitive System Information to an Unauthorized Control Sphere •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

03 Apr 2025 — HCL Traveler generates some error messages that provide detailed information about errors and failures, such as internal paths, file names, sensitive tokens, credentials, error codes, or stack traces. Attackers could exploit this information to gain insights into the system's architecture and potentially launch targeted attacks. HCL Traveler genera mensajes de error que proporcionan información detallada sobre errores y fallos, como rutas internas, nombres de archivo, tokens confidenciales, credenciales, có... • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120336 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 0

12 Nov 2024 — HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a control flow vulnerability. The application does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways. • https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0114725 • CWE-670: Always-Incorrect Control Flow Implementation •

CVSS: 6.7EPSS: 0%CPEs: 1EXPL: 0

26 Sep 2024 — The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0114723 • CWE-295: Improper Certificate Validation •