<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Gatekeeper</title>
  <link>https://cvedaily.com/pages/tags/gatekeeper.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/gatekeeper.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Gatekeeper</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-28954 – A file quarantine bypass was addressed with additional checks. This issue is fix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28954</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28954</guid>
    <pubDate>Mon, 11 May 2026 21:18:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28954</strong></p>
  <p>A file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A maliciously crafted disk image may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28954">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28914 – A logic issue was addressed with improved file handling. This issue is fixed in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28914</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28914</guid>
    <pubDate>Mon, 11 May 2026 21:18:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28914</strong></p>
  <p>A logic issue was addressed with improved file handling. This issue is fixed in macOS Tahoe 26.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-358</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28914">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42296 – Argo Workflows is an open source container-native workflow engine for orchestrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42296</guid>
    <pubDate>Sat, 09 May 2026 04:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42296</strong></p>
  <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This de…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-42183 – Argo Workflows is an open source container-native workflow engine for orchestrat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42183</guid>
    <pubDate>Sat, 09 May 2026 04:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-42183</strong></p>
  <p>Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/gatekeeper.go rbacAuthorization() causes a panic (denial of service) for SSO users whose claims match a namespace-level RBAC rule but not an SSO-namespace rule, when SSO_DELEGATE_RBAC_TO_NAMESPACE=true…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-20684 – A permissions issue was addressed with additional restrictions. This issue is fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20684</guid>
    <pubDate>Wed, 25 Mar 2026 01:17:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-20684</strong></p>
  <p>A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.4. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-47782 – Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the tra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47782</guid>
    <pubDate>Fri, 16 Jan 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47782</strong></p>
  <p>Odine Solutions GateKeeper 1.0 contains a SQL injection vulnerability in the trafficCycle API endpoint that allows remote attackers to inject malicious database queries. Attackers can exploit the vulnerability by sending crafted payloads to the /rass/api/v1/trafficCycle/ endpoint to manipulate PostgreSQL database queries and potentially extract sensitive information.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46291 – A logic issue was addressed with improved validation. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46291</guid>
    <pubDate>Wed, 17 Dec 2025 21:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46291</strong></p>
  <p>A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43348 – A logic issue was addressed with improved validation. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43348</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43348</guid>
    <pubDate>Tue, 04 Nov 2025 02:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43348</strong></p>
  <p>A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43348">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-43296 – A logic issue was addressed with improved validation. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-43296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-43296</guid>
    <pubDate>Thu, 09 Oct 2025 21:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-43296</strong></p>
  <p>A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45551 – Cryptographic issue occurs during PIN/password verification using Gatekeeper, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45551</guid>
    <pubDate>Mon, 07 Apr 2025 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45551</strong></p>
  <p>Cryptographic issue occurs during PIN/password verification using Gatekeeper, where RPMB writes can be dropped on verification failure, potentially leading to a user throttling bypass.</p>
  <p><strong>CVSS:</strong> 6.2 · <strong>CWE:</strong> CWE-1390</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24148 – This issue was addressed with improved handling of executable types. This issue ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24148</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24148</guid>
    <pubDate>Mon, 31 Mar 2025 23:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24148</strong></p>
  <p>This issue was addressed with improved handling of executable types. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious JAR file may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-354</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24148">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-49215 – In the Linux kernel, the following vulnerability has been resolved:

xsk: Fix ra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49215</guid>
    <pubDate>Wed, 26 Feb 2025 07:00:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-49215</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  xsk: Fix race at socket teardown  Fix a race in the xsk socket teardown code that can lead to a NULL pointer dereference splat. The current xsk unbind code in xsk_unbind_dev() starts by setting xs->state to XSK_UNBOUND, sets xs->dev to NULL and then waits for any NAPI processing to terminate using synchronize_net(). After that,…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-44128 – This issue was addressed by adding an additional prompt for user consent. This i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44128</guid>
    <pubDate>Tue, 17 Sep 2024 00:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-44128</strong></p>
  <p>This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7. An Automator Quick Action workflow may be able to bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-841</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-27853 – This issue was addressed with improved checks. This issue is fixed in macOS Sono...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-27853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-27853</guid>
    <pubDate>Mon, 29 Jul 2024 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-27853</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-290</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-27853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22405 – XADMaster is an objective-C library for archive and file unarchiving and extract...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22405</guid>
    <pubDate>Tue, 30 Apr 2024 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22405</strong></p>
  <p>XADMaster is an objective-C library for archive and file unarchiving and extraction. When extracting a specially crafted zip archive XADMaster may not apply quarantine attribute correctly. Such behaviour may circumvent Gatekeeper checks on the system. Only macOS installations are affected. This issue was fixed in XADMaster 1.10.8. It is recommended to upgrade to the latest version. There are no k…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-23298 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23298</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23298</guid>
    <pubDate>Fri, 15 Mar 2024 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-23298</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23298">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-23745 – In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB atta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-23745</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-23745</guid>
    <pubDate>Wed, 31 Jan 2024 02:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-23745</strong></p>
  <p>In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context. NOTE: the vendor's perspective is that this is…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-23745">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40433 – A logic issue was addressed with improved checks. This issue is fixed in macOS V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40433</guid>
    <pubDate>Wed, 10 Jan 2024 22:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40433</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-22524 – Certain versions of the Atlassian Companion App for MacOS were affected by a rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22524</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22524</guid>
    <pubDate>Wed, 06 Dec 2023 05:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-22524</strong></p>
  <p>Certain versions of the Atlassian Companion App for MacOS were affected by a remote code execution vulnerability. An attacker could utilize WebSockets to bypass Atlassian Companion’s blocklist and MacOS Gatekeeper to allow execution of code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22524">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41067 – A logic issue was addressed with improved checks. This issue is fixed in macOS S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41067</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41067</guid>
    <pubDate>Wed, 27 Sep 2023 15:19:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41067</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41067">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40450 – The issue was addressed with improved checks. This issue is fixed in macOS Sonom...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40450</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40450</guid>
    <pubDate>Wed, 27 Sep 2023 15:19:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40450</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40450">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32352 – A logic issue was addressed with improved checks. This issue is fixed in watchOS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32352</guid>
    <pubDate>Fri, 23 Jun 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32352</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in watchOS 9.5, macOS Ventura 13.4, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-27952 – A race condition was addressed with improved locking. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27952</guid>
    <pubDate>Mon, 08 May 2023 20:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-27952</strong></p>
  <p>A race condition was addressed with improved locking. This issue is fixed in macOS Ventura 13.3. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-362</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-27951 – The issue was addressed with improved checks. This issue is fixed in macOS Ventu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-27951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-27951</guid>
    <pubDate>Mon, 08 May 2023 20:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-27951</strong></p>
  <p>The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An archive may be able to bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-27951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-23526 – This was addressed with additional checks by Gatekeeper on files downloaded from...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-23526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-23526</guid>
    <pubDate>Mon, 08 May 2023 20:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-23526</strong></p>
  <p>This was addressed with additional checks by Gatekeeper on files downloaded from an iCloud shared-by-me folder. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. A file from an iCloud shared-by-me folder may be able to bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-23526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26484 – KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26484</guid>
    <pubDate>Wed, 15 Mar 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26484</strong></p>
  <p>KubeVirt is a virtual machine management add-on for Kubernetes. In versions 0.59.0 and prior, if a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components which can, for instance, read all secrets on the cluster,…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-42821 – A logic issue was addressed with improved checks. This issue is fixed in macOS M...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-42821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-42821</guid>
    <pubDate>Thu, 15 Dec 2022 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-42821</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, macOS Ventura 13. An app may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32910 – A logic issue was addressed with improved checks. This issue is fixed in macOS B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32910</guid>
    <pubDate>Tue, 01 Nov 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32910</strong></p>
  <p>A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Security Update 2022-005 Catalina. An archive may be able to bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-693</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-20377 – In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-20377</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-20377</guid>
    <pubDate>Thu, 11 Aug 2022 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-20377</strong></p>
  <p>In TBD of keymaster_ipc.cpp, there is a possible to force gatekeeper, fingerprint, and faceauth to use a known HMAC key. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222339795References: N/A</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-20377">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22663 – This issue was addressed with improved checks to prevent unauthorized actions. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22663</guid>
    <pubDate>Thu, 26 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22663</strong></p>
  <p>This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in iOS 15.4 and iPadOS 15.4, Security Update 2022-004 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.6. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22616 – This issue was addressed with improved checks. This issue is fixed in Security U...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22616</guid>
    <pubDate>Thu, 26 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22616</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. A maliciously crafted ZIP archive may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-43979 – Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency, s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-43979</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-43979</guid>
    <pubDate>Wed, 17 Nov 2021 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-43979</strong></p>
  <p>Styra Open Policy Agent (OPA) Gatekeeper through 3.7.0 mishandles concurrency, sometimes resulting in incorrect access control. The data replication mechanism allows policies to access the Kubernetes cluster state. During data replication, OPA/Gatekeeper does not wait for the replication to finish before processing a request, which might cause inconsistencies between the replicated resources in O…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-43979">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41254 – kustomize-controller is a Kubernetes operator, specialized in running continuous...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41254</guid>
    <pubDate>Fri, 12 Nov 2021 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41254</strong></p>
  <p>kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled with Kustomize. Users that can create Kubernetes Secrets, Service Accounts and Flux Kustomization objects, could execute commands inside the kustomize-controller container by embedding a shell script in a Kubernetes Se…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-33601 – A vulnerability was discovered in the web user interface of F-Secure Internet Ga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33601</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33601</guid>
    <pubDate>Tue, 28 Sep 2021 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-33601</strong></p>
  <p>A vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. An authenticated user can modify settings through the web user interface in a way that could lead to an arbitrary code execution on the F-Secure Internet Gatekeeper server.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33601">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33600 – A denial-of-service (DoS) vulnerability was discovered in the web user interface...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33600</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33600</guid>
    <pubDate>Tue, 28 Sep 2021 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33600</strong></p>
  <p>A denial-of-service (DoS) vulnerability was discovered in the web user interface of F-Secure Internet Gatekeeper. The vulnerability occurs because of an attacker can trigger assertion via malformed HTTP packet to web interface. An unauthenticated attacker could exploit this vulnerability by sending a large username parameter. A successful exploitation could lead to a denial-of-service of the prod…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-617</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33600">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30669 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30669</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30669</guid>
    <pubDate>Wed, 08 Sep 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30669</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30669">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30658 – This issue was addressed with improved handling of file metadata. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30658</guid>
    <pubDate>Wed, 08 Sep 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30658</strong></p>
  <p>This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Big Sur 11.3. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30657 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30657</guid>
    <pubDate>Wed, 08 Sep 2021 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30657</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks. Apple is aware of a report that this issue may have been actively exploited..</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-1810 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-1810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-1810</guid>
    <pubDate>Wed, 08 Sep 2021 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-1810</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.3, Security Update 2021-002 Catalina. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-1810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30990 – A logic issue was addressed with improved validation. This issue is fixed in mac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30990</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30990</strong></p>
  <p>A logic issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30976 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30976</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30976</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30976</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30976">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-30975 – This issue was addressed by disabling execution of JavaScript when viewing a scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30975</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30975</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-30975</strong></p>
  <p>This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious OSAX scripting addition may bypass Gatekeeper checks and circumvent sandbox restrictions.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30975">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30950 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30950</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30950</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.1, Security Update 2021-008 Catalina, macOS Big Sur 11.6.2. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30861 – A logic issue was addressed with improved state management. This issue is fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30861</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30861</strong></p>
  <p>A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30853 – This issue was addressed with improved checks. This issue is fixed in macOS Big ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30853</guid>
    <pubDate>Tue, 24 Aug 2021 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30853</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-14359 – A vulnerability was found in all versions of Keycloak Gatekeeper, where on using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-14359</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-14359</guid>
    <pubDate>Tue, 23 Feb 2021 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-14359</strong></p>
  <p>A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jetty). This means there is no protection when we put a Gatekeeper in front of a Jetty server and use lowercase headers.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-305</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-14359">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-1723 – A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be ab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-1723</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-1723</guid>
    <pubDate>Thu, 28 Jan 2021 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-1723</strong></p>
  <p>A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-1723">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-11123 – u'information disclosure in gatekeeper trustzone implementation as the throttlin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11123</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11123</guid>
    <pubDate>Thu, 12 Nov 2020 10:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-11123</strong></p>
  <p>u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11123">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-8656 – This was addressed with additional checks by Gatekeeper on files mounted through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8656</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8656</guid>
    <pubDate>Tue, 27 Oct 2020 20:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-8656</strong></p>
  <p>This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. Extracting a zip file containing a symbolic link to an endpoint in an NFS mount that is attacker controlled may bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8656">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13835 – An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) sof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13835</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13835</guid>
    <pubDate>Thu, 04 Jun 2020 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13835</strong></p>
  <p>An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13835">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12752 – An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12752</guid>
    <pubDate>Mon, 11 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12752</strong></p>
  <p>An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. Attackers can determine user credentials via a brute-force attack against the Gatekeeper trustlet. The Samsung ID is SVE-2020-16908 (May 2020).</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-20596 – An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-20596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-20596</guid>
    <pubDate>Tue, 24 Mar 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-20596</strong></p>
  <p>An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is information disclosure in the GateKeeper Trustlet. The Samsung ID is SVE-2019-13958 (June 2019).</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-20596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-10849 – An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10849</guid>
    <pubDate>Tue, 24 Mar 2020 18:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-10849</strong></p>
  <p>An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3866 – This was addressed with additional checks by Gatekeeper on files mounted through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3866</guid>
    <pubDate>Thu, 27 Feb 2020 21:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3866</strong></p>
  <p>This was addressed with additional checks by Gatekeeper on files mounted through a network share. This issue is fixed in macOS Catalina 10.15.3. Searching for and opening a file from an attacker controlled NFS mount may bypass Gatekeeper.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-9342 – The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9342</guid>
    <pubDate>Sat, 22 Feb 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-9342</strong></p>
  <p>The F-Secure AV parsing engine before 2020-02-05 allows virus-detection bypass via crafted Compression Method data in a GZIP archive. This affects versions before 17.0.605.474 (on Linux) of Cloud Protection For Salesforce, Email and Server Security, and Internet GateKeeper.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-436</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-8589 – This issue was addressed with improved checks. This issue is fixed in macOS Moja...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-8589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-8589</guid>
    <pubDate>Wed, 18 Dec 2019 18:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-8589</strong></p>
  <p>This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.5. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-8589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-6239 – This issue was addressed with improved handling of file metadata. This issue is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-6239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-6239</guid>
    <pubDate>Wed, 18 Dec 2019 18:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-6239</strong></p>
  <p>This issue was addressed with improved handling of file metadata. This issue is fixed in macOS Mojave 10.14.4. A malicious application may bypass Gatekeeper checks.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-6239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-2115 – In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-2115</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-2115</guid>
    <pubDate>Thu, 05 Sep 2019 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-2115</strong></p>
  <p>In GateKeeper::MintAuthToken of gatekeeper.cpp in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-415</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-2115">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-7024 – Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-7024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-7024</guid>
    <pubDate>Mon, 11 Jan 2016 11:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-7024</strong></p>
  <p>Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an unexpected directory by an application that has a valid Apple digital signature.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-7024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8838 – The Security component in Apple OS X before 10.10.2 does not properly process ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8838</guid>
    <pubDate>Fri, 30 Jan 2015 11:59:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8838</strong></p>
  <p>The Security component in Apple OS X before 10.10.2 does not properly process cached information about app certificates, which allows attackers to bypass the Gatekeeper protection mechanism by leveraging access to a revoked Developer ID certificate for signing a crafted app.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-8826 – LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8826</guid>
    <pubDate>Fri, 30 Jan 2015 11:59:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-8826</strong></p>
  <p>LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypass the Gatekeeper protection mechanism via a crafted JAR archive.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-19</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-3534 – GNU Gatekeeper before 3.1 does not limit the number of connections to the status...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3534</guid>
    <pubDate>Fri, 31 Aug 2012 20:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-3534</strong></p>
  <p>GNU Gatekeeper before 3.1 does not limit the number of connections to the status port, which allows remote attackers to cause a denial of service (connection and thread consumption) via a large number of connections.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0453 – F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authenti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0453</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0453</guid>
    <pubDate>Fri, 18 Feb 2011 17:00:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0453</strong></p>
  <p>F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obtain potentially sensitive information via a TCP session on the admin UI port.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0453">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1425 – F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1425</guid>
    <pubDate>Thu, 15 Apr 2010 21:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1425</strong></p>
  <p>F-Secure Internet Security 2010 and earlier; Anti-Virus for Microsoft Exchange 9 and earlier, and for MIMEsweeper 5.61 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, and for Linux 4.02 and earlier; Anti-Virus 2010 and earlier; Home Server Security 2009; Protection Service for Consumers 9 and earlier, for Business - Workstation security 9 and earlier, for Business - Server Security…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-1782 – Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchan...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1782</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1782</guid>
    <pubDate>Fri, 22 May 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-1782</strong></p>
  <p>Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1782">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-2838 – Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-2838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-2838</guid>
    <pubDate>Tue, 06 Jun 2006 20:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-2838</strong></p>
  <p>Buffer overflow in the web console in F-Secure Anti-Virus for Microsoft Exchange 6.40, and Internet Gatekeeper 6.40 through 6.42 and 6.50 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors.  NOTE: By default, the connections are only allowed from the local host.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-2838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-3546 – suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3546</guid>
    <pubDate>Wed, 16 Nov 2005 07:42:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-3546</strong></p>
  <p>suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-3468 – Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3468</guid>
    <pubDate>Wed, 02 Nov 2005 23:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-3468</strong></p>
  <p>Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-0326 – Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0326</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0326</guid>
    <pubDate>Tue, 23 Nov 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-0326</strong></p>
  <p>Buffer overflow in the web proxy for GateKeeper Pro 4.7 allows remote attackers to execute arbitrary code via a long GET request.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0326">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-0830 – The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-0830</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-0830</guid>
    <pubDate>Thu, 09 Sep 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-0830</strong></p>
  <p>The Content Scanner Server in F-Secure Anti-Virus for Microsoft Exchange 6.21 and earlier, F-Secure Anti-Virus for Microsoft Exchange 6.01 and earlier, and F-Secure Internet Gatekeeper 6.32 and earlier allow remote attackers to cause a denial of service (service crash due to unhandled exception) via a certain malformed packet.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-0830">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2001-0546 – Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Accel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0546</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0546</guid>
    <pubDate>Thu, 20 Sep 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2001-0546</strong></p>
  <p>Memory leak in H.323 Gatekeeper Service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (resource exhaustion) via a large amount of malformed H.323 data.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0546">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2000-0675 – Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0675</guid>
    <pubDate>Thu, 13 Jul 2000 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2000-0675</strong></p>
  <p>Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long string.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0675">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
