<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Omnissa Horizon (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/horizon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/horizon-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Omnissa Horizon (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-22420 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22420</guid>
    <pubDate>Thu, 05 Mar 2026 06:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22420</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Horizon horizon allows PHP Local File Inclusion.This issue affects Horizon: from n/a through <= 1.1.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25230 – Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25230</guid>
    <pubDate>Wed, 16 Apr 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25230</strong></p>
  <p>Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44903 – SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44903</guid>
    <pubDate>Tue, 25 Mar 2025 06:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44903</strong></p>
  <p>SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11468 – Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11468</guid>
    <pubDate>Tue, 04 Feb 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11468</strong></p>
  <p>Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11467 – Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11467</guid>
    <pubDate>Tue, 04 Feb 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11467</strong></p>
  <p>Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38891 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38891</guid>
    <pubDate>Fri, 02 Aug 2024 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38891</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38887 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38887</guid>
    <pubDate>Fri, 02 Aug 2024 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38887</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38889 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38889</guid>
    <pubDate>Fri, 02 Aug 2024 20:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38889</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38886 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38886</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38886</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38885 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38885</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38885</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38884 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38884</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38884</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38883 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38883</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38883</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-757</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38882 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38882</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38882</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38881 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38881</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38881</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38890 – An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38890</guid>
    <pubDate>Fri, 02 Aug 2024 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38890</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40313 – A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40313</guid>
    <pubDate>Thu, 17 Aug 2023 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40313</strong></p>
  <p>A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0872 – The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0872</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0872</strong></p>
  <p>The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's pri…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0870 – A form can be manipulated with cross-site request forgery in multiple versions o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0870</guid>
    <pubDate>Wed, 22 Mar 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0870</strong></p>
  <p>A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2023.1.1 or Horizon 31.0.6 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29875 – A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29875</guid>
    <pubDate>Wed, 01 Jun 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29875</strong></p>
  <p>A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22964 – VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22964</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22964</strong></p>
  <p>VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22962 – VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22962</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22962</strong></p>
  <p>VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25931 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25931</guid>
    <pubDate>Thu, 20 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25931</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at `/opennms/admin/userGroupView/users/updateUser`. This flaw allows assigning `ROLE_ADMIN` security role…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3396 – OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3396</guid>
    <pubDate>Wed, 17 Feb 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3396</strong></p>
  <p>OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3991 – VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3991</guid>
    <pubDate>Fri, 16 Oct 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3991</strong></p>
  <p>VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This will result into a denial-of-service condition on the machine where Horizon Client…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26943 – An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26943</guid>
    <pubDate>Fri, 16 Oct 2020 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26943</strong></p>
  <p>An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Ho…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3974 – VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3974</guid>
    <pubDate>Fri, 10 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3974</strong></p>
  <p>VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Rem…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3961 – VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3961</guid>
    <pubDate>Mon, 15 Jun 2020 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3961</strong></p>
  <p>VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3957 – VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3957</guid>
    <pubDate>Fri, 29 May 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3957</strong></p>
  <p>VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12760 – An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12760</guid>
    <pubDate>Mon, 11 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12760</strong></p>
  <p>An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11886 – OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11886</guid>
    <pubDate>Fri, 17 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11886</strong></p>
  <p>OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017 before 2017.1.21.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3950 – VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3950</guid>
    <pubDate>Tue, 17 Mar 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3950</strong></p>
  <p>VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Ho…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5543 – For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5543</guid>
    <pubDate>Mon, 16 Mar 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5543</strong></p>
  <p>For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed may exploit this issue to run commands as an…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3945 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3945</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3945</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3944 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3944</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3944</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3943 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3943</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3943</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5539 – VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5539</guid>
    <pubDate>Mon, 23 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5539</strong></p>
  <p>VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is ins…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5544 – OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5544</guid>
    <pubDate>Fri, 06 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5544</strong></p>
  <p>OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5527 – ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5527</guid>
    <pubDate>Thu, 10 Oct 2019 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5527</strong></p>
  <p>ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6971 – VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6971</guid>
    <pubDate>Wed, 25 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6971</strong></p>
  <p>VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6964 – VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6964</guid>
    <pubDate>Tue, 29 May 2018 20:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6964</strong></p>
  <p>VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6960 – VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6960</guid>
    <pubDate>Fri, 20 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6960</strong></p>
  <p>VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4948 – VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4948</guid>
    <pubDate>Fri, 05 Jan 2018 14:29:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4948</strong></p>
  <p>VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or may allow for a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this issue in conjunction…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4937 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4937</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4937</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4936 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4936</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4936</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4935 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4935</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4935</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4918 – VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4918</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4918</strong></p>
  <p>VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4913 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4913</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4913</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4912 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4912</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4912</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4911 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4911</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4911</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4910 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4910</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4910</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4909 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4909</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4909</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perf…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4908 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4908</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4908</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perfor…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4907 – VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon V...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4907</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4907</strong></p>
  <p>VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-7576 – DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (suc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-7576</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-7576</guid>
    <pubDate>Thu, 06 Apr 2017 22:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-7576</strong></p>
  <p>DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions including 1.4.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-7576">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-3650 – vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3650</guid>
    <pubDate>Fri, 10 Jul 2015 17:59:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-3650</strong></p>
  <p>vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows host OS users to gain host OS privileges by injecting a thread.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2013-7139 – SQL injection vulnerability in download.php in Horizon Quick Content Management ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7139</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7139</guid>
    <pubDate>Thu, 09 Jan 2014 18:55:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2013-7139</strong></p>
  <p>SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7139">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2013-7136 – The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7136</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7136</guid>
    <pubDate>Thu, 19 Dec 2013 22:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2013-7136</strong></p>
  <p>The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-310</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7136">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-2026 – Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2026</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2026</guid>
    <pubDate>Thu, 16 Jun 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-2026</strong></p>
  <p>Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2026">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
