Vulnerabilities > Cordaware

DATE CVE VULNERABILITY TITLE RISK
2019-02-25 CVE-2019-6266 Improper Certificate Validation vulnerability in Cordaware Bestinformed
Cordaware bestinformed Microsoft Windows client before 6.2.1.0 is affected by insecure SSL certificate verification and insecure access patterns.
network
low complexity
cordaware CWE-295
critical
9.8
2019-02-25 CVE-2019-6265 Unspecified vulnerability in Cordaware Bestinformed
The Scripting and AutoUpdate functionality in Cordaware bestinformed Microsoft Windows client versions before 6.2.1.0 are affected by insecure implementations which allow remote attackers to execute arbitrary commands and escalate privileges.
local
low complexity
cordaware
7.8