Vulnerabilities (CVE)

Filtered by vendor Nomachine Subscribe
Filtered by product Nx Web Companion
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-5003 1 Nomachine 1 Nx Web Companion 2023-12-10 6.8 MEDIUM N/A
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.