Incomplete in the CWE catalog · 29 CVEs mapped
The product's user interface does not warn the user before undertaking an unsafe action on behalf of that user. This makes it easier for attackers to trick users into inflicting damage to their system.
Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of attachments. When opening an attachment, the user interface fails to warn the user of unsafe actions. An attacker can leverage this vulnerability to execute code in the context of current user. Was ZDI-CAN-26034.
Zed is a multiplayer code editor. Prior to 0.219.4, Zed does not show with which parameters a tool is being invoked, when asking for allowance. Further it does not show after the tool was being invoked, which parameters were used. Thus, maybe unwanted or even malicious values could be used without the user having a chance to notice it. Patched in Zed Editor 0.219.4 which includes expandable tool call details.
⚡ A design flaw in Epiphany is like a sly magician inviting you to a show, only for the trick to go horribly wrong! 🎩 Think of Epiphany as a concierge at a hotel, directing guests to external services with a friendly smile. But what if that concierge inadvertently hands guests a key to a secret room full of chaos, allowing any unwelcome entity to step right through? If exploited, an attacker could potentially execute arbitrary code on your device, making it an open invitation to compromise sensitive data or take control of your system. With no proper warnings in place, users might unknowingly grant access, opening the floodgates to a world of trouble!