cve,link,title,description,vendor,products,score,severity,epss,cisa,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2022-3421,https://securityvulnerability.io/vulnerability/CVE-2022-3421,Privilege escalation in Google Drive for Desktop on MacOS,"An attacker can pre-create the `/Applications/Google\ Drive.app/Contents/MacOS` directory which is expected to be owned by root to be owned by a non-root user. When the Drive for Desktop installer is run for the first time, it will place a binary in that directory with execute permissions and set its setuid bit. Since the attacker owns the directory, the attacker can replace the binary with a symlink, causing the installer to set the setuid bit on the symlink. When the symlink is executed, it will run with root permissions. We recommend upgrading past version 64.0",Google,Drive For Desktop Mac OS,5.6,MEDIUM,0.0004400000034365803,false,false,false,false,,false,false,2022-10-17T00:00:00.000Z,0 CVE-2007-3150,https://securityvulnerability.io/vulnerability/CVE-2007-3150,,"Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV=""refresh"" that targets a www.google.com search for a local .exe file, which is displayed in the ""results stored on your computer"" portion of the search results, and when clicked invokes Google Desktop to execute this file.",Google,Desktop,,,0.003289999905973673,false,false,false,false,,false,false,2007-06-11T19:00:00.000Z,0 CVE-2007-1085,https://securityvulnerability.io/vulnerability/CVE-2007-1085,,"Cross-site scripting (XSS) vulnerability in Google Desktop allows remote attackers to bypass protection schemes and inject arbitrary web script or HTML, and possibly gain full access to the system, by using an XSS vulnerability in google.com to extract the signature for the internal web server, then calling the ""under"" parameter in Advanced Search with the proper signature.",Google,Desktop,,,0.03874000161886215,false,false,false,false,,false,false,2007-02-23T01:00:00.000Z,0