CVE-2024-3461
- EPSS 0.01%
- Veröffentlicht 14.05.2024 15:41:13
- Zuletzt bearbeitet 12.02.2025 15:37:59
KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.
CVE-2024-3459
- EPSS 0.08%
- Veröffentlicht 14.05.2024 15:41:12
- Zuletzt bearbeitet 12.02.2025 01:48:00
KioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened in an external PDF viewer. By using built-in functions of that viewer it is possible to launch a web browser, ...
- EPSS 0.05%
- Veröffentlicht 14.05.2024 15:41:12
- Zuletzt bearbeitet 12.02.2025 15:36:15
In KioWare for Windows (versions all through 8.34) it is possible to exit this software and use other already opened applications utilizing a short time window before the forced automatic logout occurs. Then, by using some built-in function of these ...
CVE-2023-34641
- EPSS 0.05%
- Veröffentlicht 19.06.2023 05:15:09
- Zuletzt bearbeitet 12.12.2024 01:23:47
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function window.print() which can then be used to open...
CVE-2023-34642
- EPSS 0.06%
- Veröffentlicht 19.06.2023 05:15:09
- Zuletzt bearbeitet 12.12.2024 01:23:47
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can then be used ...
CVE-2022-44875
- EPSS 1.47%
- Veröffentlicht 06.03.2023 05:15:11
- Zuletzt bearbeitet 06.03.2025 21:15:12
KioWare through 8.33 on Windows sets KioScriptingUrlACL.AclActions.AllowHigh for the about:blank origin, which allows attackers to obtain SYSTEM access via KioUtils.Execute in JavaScript code.