<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – VMware Photon</title>
  <link>https://cvedaily.com/pages/tags/photon.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/photon.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – VMware Photon</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:08 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2023-34060 – VMware Cloud Director Appliance contains an authentication bypass vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34060</guid>
    <pubDate>Tue, 14 Nov 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34060</strong></p>
  <p>VMware Cloud Director Appliance contains an authentication bypass vulnerability in case VMware Cloud Director Appliance was upgraded to 10.5 from an older version. On an upgraded version of VMware Cloud Director Appliance 10.5, a malicious actor with network access to the appliance can bypass login restrictions when authenticating on port 22 (ssh) or port 5480 (appliance management console) . Thi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-46055 – An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46055</guid>
    <pubDate>Sat, 21 Oct 2023 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-46055</strong></p>
  <p>An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24374 – Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon W...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24374</guid>
    <pubDate>Thu, 06 Apr 2023 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24374</strong></p>
  <p>Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24382 – Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Ico...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24382</guid>
    <pubDate>Tue, 14 Feb 2023 12:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24382</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Photon WP Material Design Icons for Page Builders plugin <= 1.4.2 versions.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22055 – The SchedulerServer in Vmware photon allows remote attackers to inject logs thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22055</guid>
    <pubDate>Mon, 11 Apr 2022 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22055</strong></p>
  <p>The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attackers can also insert malicious data and fake entries.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-21983 – Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-21983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-21983</guid>
    <pubDate>Wed, 31 Mar 2021 18:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-21983</strong></p>
  <p>Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authenticated malicious actor with network access to the vRealize Operations Manager API can write files to arbitrary locations on the underlying photon operating system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-21983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-5637 – The Newphoria Photon application before 1.2 for Android allows attackers to bypa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5637</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5637</guid>
    <pubDate>Sun, 20 Sep 2015 17:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-5637</strong></p>
  <p>The Newphoria Photon application before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5637">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-2688 – Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-2688</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-2688</guid>
    <pubDate>Fri, 12 Jul 2013 16:56:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-2688</strong></p>
  <p>Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon device file.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-2688">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-0619 – Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0619</guid>
    <pubDate>Thu, 09 Feb 2006 02:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-0619</strong></p>
  <p>Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the libph library.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1681 – Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1681</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1681</guid>
    <pubDate>Thu, 26 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1681</strong></p>
  <p>Multiple buffer overflows in (1) phrelay-cfg, (2) phlocale, (3) pkg-installer, or (4) input-cfg in QNX Photon microGUI for QNX RTP 6.1 allow local users to gain privileges via a long -s (server) command line parameter.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1681">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2002-2409 – Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-2409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-2409</guid>
    <pubDate>Tue, 31 Dec 2002 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2002-2409</strong></p>
  <p>Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-2409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2000-0904 – Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web clie...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0904</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2000-0904</strong></p>
  <p>Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0904">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
