Latest CVE Feed
-
4.3
MEDIUMCVE-2022-2787
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.... Read more
- Published: Aug. 27, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2606
Jenkins before versions 2.44, 2.32.2 is vulnerable to an information exposure in the internal API that allows access to item names that should not be visible (SECURITY-380). This only affects anonymous users (other users legitimately have access) that wer... Read more
Affected Products : jenkins- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-27769
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.... Read more
- Published: May. 14, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-2590
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows unauthent... Read more
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-5928
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 prot... Read more
Affected Products : high_resolution_time_api- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-50761
The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, Thunderbird did not compare the signature creation date with the message date and time, and displayed a valid signature despi... Read more
- Published: Dec. 19, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2023-4904
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)... Read more
- Published: Sep. 12, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0587
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47145
Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.... Read more
- Published: Sep. 26, 2024
- Modified: Sep. 26, 2024
-
4.3
MEDIUMCVE-2017-3261
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticat... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2023-2022
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on ... Read more
Affected Products : gitlab- Published: Aug. 02, 2023
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8735
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user by redirecting the user to a specially crafted website, due to the way that Microsoft Edge parses HTTP content, aka "Microsoft Edge S... Read more
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2018-0571
baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.... Read more
Affected Products : basercms- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-2611
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins ... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-24654
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.... Read more
- Published: Sep. 02, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2020-15192
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not prope... Read more
- Published: Sep. 25, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2024-47803
Jenkins 2.478 and earlier, LTS 2.462.2 and earlier does not redact multi-line secret values in error messages generated for form submissions involving the `secretTextarea` form field.... Read more
Affected Products : jenkins- Published: Oct. 02, 2024
- Modified: Mar. 19, 2025
-
4.3
MEDIUMCVE-2017-8761
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployments using the tempurl middleware ar... Read more
Affected Products : swift- Published: Jun. 02, 2021
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8662
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to disclose information due to how strings are validated in specific scenarios, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017... Read more
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3323
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: General). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier and 7.4.12 and earlier. Difficult to exploit vulnerability allows unauthenticate... Read more
Affected Products : mysql_cluster- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025