<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Omnissa Horizon</title>
  <link>https://cvedaily.com/pages/tags/horizon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/horizon.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Omnissa Horizon</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:52 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-43002 – An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43002</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43002</guid>
    <pubDate>Tue, 05 May 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43002</strong></p>
  <p>An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthenticated requests. This is a regression of the CVE-2014-8124 fix.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-696</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43002">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22420 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22420</guid>
    <pubDate>Thu, 05 Mar 2026 06:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22420</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Horizon horizon allows PHP Local File Inclusion.This issue affects Horizon: from n/a through <= 1.1.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-58131 – Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58131</guid>
    <pubDate>Tue, 09 Sep 2025 22:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-58131</strong></p>
  <p>Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or before 6.2.15 and 6.3.12 in their respective tracks) may allow an authenticated user to conduct a disclosure of information via network access.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53122 – Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53122</guid>
    <pubDate>Thu, 26 Jun 2025 20:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53122</strong></p>
  <p>Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenNMS Horizon and Meridian applications allows SQL Injection.   Users should upgrade to Meridian 2024.2.6 or newer, or Horizon 33.16 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53121 – Multiple stored XSS were found on different nodes with unsanitized parameters in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53121</guid>
    <pubDate>Thu, 26 Jun 2025 19:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53121</strong></p>
  <p>Multiple stored XSS were found on different nodes with unsanitized parameters in OpenMNS Horizon 33.0.8 and versions earlier than 33.1.6 on multiple platforms that allow an attacker to store on database and then inject HTML and/or Javascript on the page. The solution is to upgrade to Horizon 33.1.6, 33.1.7 or Meridian 2024.2.6, 2024.2.7 or newer. Meridian and Horizon installation instructions sta…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25230 – Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25230</guid>
    <pubDate>Wed, 16 Apr 2025 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25230</strong></p>
  <p>Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44903 – SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44903</guid>
    <pubDate>Tue, 25 Mar 2025 06:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44903</strong></p>
  <p>SQL Injection can occur in the SirsiDynix Horizon Information Portal (IPAC20) through 3.25_9382; however, a patch is available from the vendor. This is in ipac.jsp in a SELECT WHERE statement, in a part of the uri= variable in the second part of the full= inner variable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11468 – Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11468</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11468</guid>
    <pubDate>Tue, 04 Feb 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11468</strong></p>
  <p>Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11468">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-11467 – Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11467</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11467</guid>
    <pubDate>Tue, 04 Feb 2025 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-11467</strong></p>
  <p>Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11467">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38891 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38891</guid>
    <pubDate>Fri, 02 Aug 2024 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38891</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Sniffing Network Traffic attack due to the cleartext transmission of sensitive information.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-319</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38887 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38887</guid>
    <pubDate>Fri, 02 Aug 2024 21:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38887</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to expand control over the operating system from the database due to the execution of commands with unnecessary privileges.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38889 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38889</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38889</guid>
    <pubDate>Fri, 02 Aug 2024 20:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38889</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of special elements used in an SQL command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38889">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38888 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38888</guid>
    <pubDate>Fri, 02 Aug 2024 20:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38888</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform a Password Brute Forcing attack due to improper restriction of excessive authentication attempts.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38886 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38886</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38886</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verification of the source of a communication channel.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38885 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38885</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38885</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform unauthorized access using known operating system credentials due to hardcoded SQL user credentials in the client application.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-259</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38884 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38884</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38884</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38884</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a local attacker to perform an Authentication Bypass attack due to improperly implemented security checks for standard authentication mechanisms</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38884">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38883 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38883</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38883</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38883</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Drop Encryption Level attack due to the selection of a less-secure algorithm during negotiation.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-757</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38883">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38882 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38882</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38882</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform command line execution through SQL Injection due to improper neutralization of special elements used in an OS command.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38881 – An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38881</guid>
    <pubDate>Fri, 02 Aug 2024 18:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38881</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Rainbow Table Password cracking attack due to the use of one-way hashes without salts when storing user passwords.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-760</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38890 – An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 throug...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38890</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38890</guid>
    <pubDate>Fri, 02 Aug 2024 15:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38890</strong></p>
  <p>An issue in Horizon Business Services Inc. Caterease Software 16.0.1.1663 through 24.0.1.2405 and possibly later versions allows a local attacker to perform an Authentication Bypass by Capture-replay attack due to insufficient protection against capture-replay attacks.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-294</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38890">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40314 – Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40314</guid>
    <pubDate>Thu, 16 Nov 2023 22:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40314</strong></p>
  <p>Cross-site scripting in bootstrap.jsp in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Horizon 32.0.5 or newer and Meridian 2023.1.9 or newer           Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40612 – In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor whic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40612</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40612</guid>
    <pubDate>Wed, 23 Aug 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40612</strong></p>
  <p>In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection attacks. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks a…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40612">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-45582 – Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45582</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45582</guid>
    <pubDate>Tue, 22 Aug 2023 19:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45582</strong></p>
  <p>Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45582">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40315 – In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40315</guid>
    <pubDate>Thu, 17 Aug 2023 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40315</strong></p>
  <p>In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 and related Meridian versions, any user that has the ROLE_FILESYSTEM_EDITOR can easily escalate their privileges to ROLE_ADMIN or any other role. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40313 – A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40313</guid>
    <pubDate>Thu, 17 Aug 2023 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40313</strong></p>
  <p>A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40312 – Multiple reflected XSS were found on different JSP files with unsanitized parame...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40312</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40312</strong></p>
  <p>Multiple reflected XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that an attacker can modify to craft a malicious XSS payload. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40311 – Multiple stored XSS were found on different JSP files with unsanitized parameter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40311</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40311</strong></p>
  <p>Multiple stored XSS were found on different JSP files with unsanitized parameters in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms that allow an attacker to store on database and then load on JSPs or Angular templates. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instr…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0872 – The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0872</guid>
    <pubDate>Mon, 14 Aug 2023 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0872</strong></p>
  <p>The Horizon REST API includes a users endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to elevation of privilege. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's pri…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0871 – XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0871</guid>
    <pubDate>Fri, 11 Aug 2023 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0871</strong></p>
  <p>XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external entity (XXE) injection, which can be used for instance to force Horizon to make arbitrary HTTP requests to internal and external services. The solution is to upgrade to Meridian 2023.1.6, 2022.1.19, 2021.1.30, 2020.1.38 or Horizon 32.0.2 or newer. Mer…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34038 – VMware Horizon Server contains an information disclosure vulnerability. A malici...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34038</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34038</guid>
    <pubDate>Fri, 04 Aug 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34038</strong></p>
  <p>VMware Horizon Server contains an information disclosure vulnerability. A malicious actor with network access may be able to access information relating to the internal network configuration.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34038">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34037 – VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34037</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34037</guid>
    <pubDate>Fri, 04 Aug 2023 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34037</strong></p>
  <p>VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with network access may be able to perform HTTP smuggle requests.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-444</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34037">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-0870 – A form can be manipulated with cross-site request forgery in multiple versions o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0870</guid>
    <pubDate>Wed, 22 Mar 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-0870</strong></p>
  <p>A form can be manipulated with cross-site request forgery in multiple versions of OpenNMS Meridian and Horizon. This can potentially allow an attacker to gain access to confidential information and compromise integrity. The solution is to upgrade to Meridian 2023.1.1 or Horizon 31.0.6 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0870">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0869 – Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0869</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0869</guid>
    <pubDate>Thu, 23 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0869</strong></p>
  <p>Cross-site scripting in outage/list.htm in multiple versions of OpenNMS Meridian and Horizon allows an attacker access to confidential session information. The solution is to upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4 or newer.             Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0869">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0868 – Reflected cross-site scripting in graph results in multiple versions of OpenNMS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0868</guid>
    <pubDate>Thu, 23 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0868</strong></p>
  <p>Reflected cross-site scripting in graph results in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to steal session cookies. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessib…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0867 – Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0867</guid>
    <pubDate>Thu, 23 Feb 2023 15:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0867</strong></p>
  <p>Multiple stored and reflected cross-site scripting vulnerabilities in webapp jsp pages in multiple versions of OpenNMS Meridian and Horizon could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's pr…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0815 – Potential Insertion of Sensitive Information into Jetty Log Files in multiple ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0815</guid>
    <pubDate>Thu, 23 Feb 2023 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0815</strong></p>
  <p>Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's pri…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-0846 – Unauthenticated, stored cross-site scripting in the display of alarm reduction k...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0846</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0846</guid>
    <pubDate>Wed, 22 Feb 2023 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-0846</strong></p>
  <p>Unauthenticated, stored cross-site scripting in the display of alarm reduction keys in multiple versions of OpenNMS Horizon and Meridian could allow an attacker access to confidential session information. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's priva…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0846">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2014-125078 – A vulnerability was found in yanheven console and classified as problematic. Aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-125078</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-125078</guid>
    <pubDate>Sun, 15 Jan 2023 09:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2014-125078</strong></p>
  <p>A vulnerability was found in yanheven console and classified as problematic. Affected by this issue is some unknown functionality of the file horizon/static/horizon/js/horizon.instances.js. The manipulation leads to cross site scripting. The attack may be launched remotely. The patch is identified as 32a7b713468161282f2ea01d5e2faff980d924cd. It is recommended to apply a patch to fix this issue. V…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-125078">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-34302 – A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-34302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-34302</guid>
    <pubDate>Fri, 26 Aug 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-34302</strong></p>
  <p>A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace the existing signed bootloader currently in use with this bootloader. Access to the EFI System Partition is required for booting using exte…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-34302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-1655 – An Incorrect Permission Assignment for Critical Resource flaw was found in Horiz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1655</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1655</guid>
    <pubDate>Fri, 22 Jul 2022 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-1655</strong></p>
  <p>An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1655">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22217 – An Improper Check for Unusual or Exceptional Conditions vulnerability in the Pac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22217</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22217</guid>
    <pubDate>Wed, 20 Jul 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22217</strong></p>
  <p>An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packets looping on a multi-homed Ethernet Segment Identifier (ESI) when VXLAN is configured. These MLD packets received on a multi-homed ESI are…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22217">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-29875 – A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29875</guid>
    <pubDate>Wed, 01 Jun 2022 10:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-29875</strong></p>
  <p>A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22964 – VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22964</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22964</strong></p>
  <p>VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-22962 – VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escala...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22962</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-22962</strong></p>
  <p>VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-59</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22938 – VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22938</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22938</guid>
    <pubDate>Fri, 28 Jan 2022 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22938</strong></p>
  <p>VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual machine or remote desktop may exploit this issue to trigger a denial-of-service condition in the Thinprint service running on the host machin…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22938">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-0295 – A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Jun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0295</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0295</guid>
    <pubDate>Thu, 15 Jul 2021 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-0295</strong></p>
  <p>A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos OS on the QFX10K Series switches allows an attacker to trigger a packet forwarding loop, leading to a partial Denial of Service (DoS). The issue is caused by DVMRP packets looping on a multi-homed Ethernet Segment Identifier (ESI) when VXLAN is configured. DVMRP packets received on a multi-homed ES…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0295">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32738 – js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32738</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32738</guid>
    <pubDate>Fri, 02 Jul 2021 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32738</strong></p>
  <p>js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the `serverAccountID` has signed the transaction. In js-stellar-sdk before version 8.2.3, the function does not veri…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32738">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25932 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25932</guid>
    <pubDate>Tue, 01 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25932</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `userID…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25935 – In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25935</guid>
    <pubDate>Tue, 25 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25935</strong></p>
  <p>In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `add()` performs improper validation checks on the input sent to the `foreign-source` parame…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25934 – In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25934</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25934</guid>
    <pubDate>Tue, 25 May 2021 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25934</strong></p>
  <p>In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `createRequisitionedNode()` does not perform any validation checks on the input sent to the…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25934">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21989 – VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21989</guid>
    <pubDate>Mon, 24 May 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21989</strong></p>
  <p>VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon C…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21988 – VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21988</guid>
    <pubDate>Mon, 24 May 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21988</strong></p>
  <p>VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (JPEG2000 Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Hori…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21987 – VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21987</guid>
    <pubDate>Mon, 24 May 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21987</strong></p>
  <p>VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be able to exploit these issues leading to information disclosure from the TPView process running on the system where Workstation or Horizon C…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25933 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25933</guid>
    <pubDate>Thu, 20 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25933</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting, since the function `validateFormInput()` performs improper validation checks on the input sent to the `groupN…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-25931 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25931</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25931</guid>
    <pubDate>Thu, 20 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-25931</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at `/opennms/admin/userGroupView/users/updateUser`. This flaw allows assigning `ROLE_ADMIN` security role…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25931">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25929 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25929</guid>
    <pubDate>Thu, 20 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25929</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to Stored Cross-Site Scripting since there is no validation on the input being sent to the `name` parameter in `noticeWizard` endpoint. Due t…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-25930 – In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNM...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-25930</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-25930</guid>
    <pubDate>Thu, 20 May 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-25930</strong></p>
  <p>In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection, and since there is no validation of an existing user name while renaming a user. As a result, privileges…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-25930">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-3396 – OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-3396</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-3396</guid>
    <pubDate>Wed, 17 Feb 2021 21:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-3396</strong></p>
  <p>OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-3396">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-29565 – An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29565</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29565</guid>
    <pubDate>Fri, 04 Dec 2020 08:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-29565</strong></p>
  <p>An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply a malicious URL in Horizon that can cause an automatic redirect to the provided malicious URL.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29565">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3998 – VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3998</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3998</guid>
    <pubDate>Fri, 23 Oct 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3998</strong></p>
  <p>VMware Horizon Client for Windows (5.x prior to 5.5.0) contains an information disclosure vulnerability. A malicious attacker with local privileges on the machine where Horizon Client for Windows is installed may be able to retrieve hashed credentials if the client crashes.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3998">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3997 – VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3997</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3997</guid>
    <pubDate>Fri, 23 Oct 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3997</strong></p>
  <p>VMware Horizon Server (7.x prior to 7.10.3 or 7.13.0) contains a Cross Site Scripting (XSS) vulnerability. Successful exploitation of this issue may allow an attacker to inject malicious script which will be executed.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3997">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3991 – VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-servic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3991</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3991</guid>
    <pubDate>Fri, 16 Oct 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3991</strong></p>
  <p>VMware Horizon Client for Windows (5.x before 5.5.0) contains a denial-of-service vulnerability due to a file system access control issue during install time. Successful exploitation of this issue may allow an attacker to overwrite certain admin privileged files through a symbolic link attack at install time. This will result into a denial-of-service condition on the machine where Horizon Client…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3991">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-26943 – An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-26943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-26943</guid>
    <pubDate>Fri, 16 Oct 2020 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-26943</strong></p>
  <p>An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Ho…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-26943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3977 – VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3977</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3977</guid>
    <pubDate>Tue, 22 Sep 2020 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3977</strong></p>
  <p>VMware Horizon DaaS (7.x and 8.x before 8.0.1 Update 1) contains a broken authentication vulnerability due to a flaw in the way it handled the first factor authentication. Successful exploitation of this issue may allow an attacker to bypass two-factor authentication process. In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3977">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3990 – VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3990</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3990</guid>
    <pubDate>Wed, 16 Sep 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3990</strong></p>
  <p>VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process running on the system where Workstation or Horizon Client for Windows is installed.…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3990">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-3989 – VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3989</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3989</guid>
    <pubDate>Wed, 16 Sep 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-3989</strong></p>
  <p>VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service condition on the system where Workstation or Horizon Client for Windows is installe…</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3989">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3988 – VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3988</guid>
    <pubDate>Wed, 16 Sep 2020 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3988</strong></p>
  <p>VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizo…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3987 – VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3987</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3987</guid>
    <pubDate>Wed, 16 Sep 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3987</strong></p>
  <p>VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3987">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-3986 – VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) cont...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3986</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3986</guid>
    <pubDate>Wed, 16 Sep 2020 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-3986</strong></p>
  <p>VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak memory from TPView process running on the system where Workstation or Horizon Cli…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3986">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3974 – VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3974</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3974</guid>
    <pubDate>Fri, 10 Jul 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3974</strong></p>
  <p>VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior before 11.2.0 ) and Horizon Client for Mac (5.x and prior before 5.4.3) contain a privilege escalation vulnerability due to improper XPC Client validation. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMware Rem…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3974">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3961 – VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3961</guid>
    <pubDate>Mon, 15 Jun 2020 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3961</strong></p>
  <p>VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe loading of libraries. A local user on the system where the software is installed may exploit this issue to run commands as any user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3957 – VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3957</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3957</guid>
    <pubDate>Fri, 29 May 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3957</strong></p>
  <p>VMware Fusion (11.x before 11.5.5), VMware Remote Console for Mac (11.x and prior) and VMware Horizon Client for Mac (5.x and prior) contain a local privilege escalation vulnerability due to a Time-of-check Time-of-use (TOCTOU) issue in the service opener. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3957">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12760 – An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 20...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12760</guid>
    <pubDate>Mon, 11 May 2020 16:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12760</strong></p>
  <p>An issue was discovered in OpenNMS Horizon before 26.0.1, and Meridian before 2018.1.19 and 2019 before 2019.1.7. The ActiveMQ channel configuration allowed for arbitrary deserialization of Java objects (aka ActiveMQ Minion payload deserialization), leading to remote code execution for any authenticated channel user regardless of its assigned permissions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11886 – OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11886</guid>
    <pubDate>Fri, 17 Apr 2020 20:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11886</strong></p>
  <p>OpenNMS Horizon and Meridian allows HQL Injection in element/nodeList.htm (aka the NodeListController) via snmpParm or snmpParmValue to addCriteriaForSnmpParm. This affects Horizon before 25.2.1, Meridian 2019 before 2019.1.4, Meridian 2018 before 2018.1.16, and Meridian 2017 before 2017.1.21.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2020-3951 – VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3951</guid>
    <pubDate>Tue, 17 Mar 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2020-3951</strong></p>
  <p>VMware Workstation (15.x before 15.5.2) and Horizon Client for Windows (5.x and prior before 5.4.0) contain a denial-of-service vulnerability due to a heap-overflow issue in Cortado Thinprint. Attackers with non-administrative access to a guest VM with virtual printing enabled may exploit this issue to create a denial-of-service condition of the Thinprint service running on the system where Works…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3950 – VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3950</guid>
    <pubDate>Tue, 17 Mar 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3950</strong></p>
  <p>VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for Mac (5.x and prior before 5.4.0) contain a privilege escalation vulnerability due to improper use of setuid binaries. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to root on the system where Fusion, VMRC or Ho…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5543 – For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5543</guid>
    <pubDate>Mon, 16 Mar 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5543</strong></p>
  <p>For VMware Horizon Client for Windows (5.x and prior before 5.3.0), VMware Remote Console for Windows (10.x before 11.0.0), VMware Workstation for Windows (15.x before 15.5.2) the folder containing configuration files for the VMware USB arbitration service was found to be writable by all users. A local user on the system where the software is installed may exploit this issue to run commands as an…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3945 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3945</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3945</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) contains an information disclosure vulnerability due to incorrect pairing implementation between the vRealize Operations for Horizon Adapter and Horizon View. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may obtain sensitive information</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-3944 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3944</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-3944</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) has an improper trust store configuration leading to authentication bypass. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to bypass Adapter authentication.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-3943 – vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-3943</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-3943</guid>
    <pubDate>Wed, 19 Feb 2020 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-3943</strong></p>
  <p>vRealize Operations for Horizon Adapter (6.7.x prior to 6.7.1 and 6.6.x prior to 6.6.1) uses a JMX RMI service which is not securely configured. An unauthenticated remote attacker who has network access to vRealize Operations, with the Horizon Adapter running, may be able to execute arbitrary code in vRealize Operations.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-3943">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-5474 – The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platfo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-5474</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-5474</guid>
    <pubDate>Mon, 30 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-5474</strong></p>
  <p>The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-5474">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5539 – VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5539</guid>
    <pubDate>Mon, 23 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5539</strong></p>
  <p>VMware Workstation (15.x prior to 15.5.1) and Horizon View Agent (7.10.x prior to 7.10.1 and 7.5.x prior to 7.5.4) contain a DLL hijacking vulnerability due to insecure loading of a DLL by Cortado Thinprint. Successful exploitation of this issue may allow attackers with normal user privileges to escalate their privileges to administrator on a Windows machine where Workstation or View Agent is ins…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-5544 – OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite iss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5544</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5544</guid>
    <pubDate>Fri, 06 Dec 2019 16:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-5544</strong></p>
  <p>OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5544">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-5527 – ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vuln...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5527</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5527</guid>
    <pubDate>Thu, 10 Oct 2019 17:15:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-5527</strong></p>
  <p>ESXi, Workstation, Fusion, VMRC and Horizon Client contain a use-after-free vulnerability in the virtual sound device. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.5.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5527">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5513 – VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5513</guid>
    <pubDate>Tue, 09 Apr 2019 20:30:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5513</strong></p>
  <p>VMware Horizon Connection Server (7.x before 7.8, 7.5.x before 7.5.2, 6.x before 6.2.8) contains an information disclosure vulnerability. Successful exploitation of this issue may allow disclosure of internal domain names, the Connection Server’s internal name, or the gateway’s internal IP address.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6970 – VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horiz...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6970</guid>
    <pubDate>Mon, 13 Aug 2018 21:48:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6970</strong></p>
  <p>VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6971 – VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6971</guid>
    <pubDate>Wed, 25 Jul 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6971</strong></p>
  <p>VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during th…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6964 – VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6964</guid>
    <pubDate>Tue, 29 May 2018 20:29:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6964</strong></p>
  <p>VMware Horizon Client for Linux (4.x before 4.8.0 and prior) contains a local privilege escalation vulnerability due to insecure usage of SUID binary. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on a Linux machine where Horizon Client is installed.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6960 – VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerab...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6960</guid>
    <pubDate>Fri, 20 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6960</strong></p>
  <p>VMware Horizon DaaS (7.x before 8.0.0) contains a broken authentication vulnerability that may allow an attacker to bypass two-factor authentication. Note: In order to exploit this issue, an attacker must have a legitimate account on Horizon DaaS.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4948 – VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4948</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4948</guid>
    <pubDate>Fri, 05 Jan 2018 14:29:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4948</strong></p>
  <p>VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll. On Workstation, this issue in conjunction with other bugs may allow a guest to leak information from host or may allow for a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this issue in conjunction…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4948">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4937 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4937</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4937</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4936 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4936</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4936</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4935 – VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4935</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4935</guid>
    <pubDate>Fri, 17 Nov 2017 14:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4935</strong></p>
  <p>VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4935">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-4918 – VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4918</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4918</guid>
    <pubDate>Thu, 08 Jun 2017 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-4918</strong></p>
  <p>VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX system where the client is installed.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4918">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4913 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4913</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4913</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4913</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4913">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4912 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4912</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4912</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4912</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4912">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4911 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4911</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4911</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4911</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4911">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4910 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4910</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4910</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4909 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4909</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4909</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perf…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-4908 – VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-4908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-4908</guid>
    <pubDate>Thu, 08 Jun 2017 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-4908</strong></p>
  <p>VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perfor…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-4908">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
