spaceraccoon

2 exploits Active since Mar 2020
CVE-2020-10665 NOMISEC MEDIUM WORKING POC
Docker Desktop <2.1.0.9-2.2.2.0 - Privilege Escalation
Docker Desktop allows local privilege escalation to NT AUTHORITY\SYSTEM because it mishandles the collection of diagnostics with Administrator privileges, leading to arbitrary DACL permissions overwrites and arbitrary file writes. This affects Docker Desktop Enterprise before 2.1.0.9, Docker Desktop for Windows Stable before 2.2.0.4, and Docker Desktop for Windows Edge before 2.2.2.0.
54 stars
CVSS 6.7
CVE-2024-4367 NOMISEC HIGH SCANNER
Firefox < 126 and ESR < 115.11 - Arbitrary JavaScript Execution in PDF.js via Missing Type Check
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
11 stars
CVSS 8.8