← Vulnerability feed

Vulnerability record · CVE-2018-0664 · published 4 September 2018

CVE-2018-0664: Nomachine improper input validation vulnerability

Nomachine · Nomachine

A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.

9.8 CVSS 3.0 Critical EPSS 1.7% · top 24.4% CWE-20 · Improper input validation
9.8CVSS 3.0 base score, v2 7.5
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in NoMachine App for Android 5.0.63 and earlier allows attackers to alter environment variables via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://jvn.jp/en/jp/JVN14451678/index.html Third Party AdvisoryVDB Entry
https://www.nomachine.com/TR06P08619 Vendor Advisory
http://jvn.jp/en/jp/JVN14451678/index.html Third Party AdvisoryVDB Entry
https://www.nomachine.com/TR06P08619 Vendor Advisory

Track CVE-2018-0664 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2023-39107Nomachine link following vulnerabilityAn arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-…EPSS 1.2%8.8CVE-2017-12763Nomachine incorrect default permissions vulnerabilityAn unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loc…EPSS 3.9%7.8CVE-2026-5055Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.20%7.8CVE-2026-5054Nomachine vulnerabilityNoMachine External Control of File Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on…EPSS 0.17%7.8CVE-2025-8614Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.27%7.8CVE-2024-7253Nomachine uncontrolled search path element vulnerabilityNoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges…EPSS 0.35%7.8CVE-2018-17980Nomachine untrusted search path vulnerabilityNoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory a…EPSS 4.6%7.8CVE-2018-6947Nomachine vulnerabilityAn uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2 and earlier a…EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2018-0664), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.