Latest CVE Feed
-
4.3
MEDIUMCVE-2018-1000109
An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.... Read more
Affected Products : google-play-android-publisher- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-1000108
A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.... Read more
Affected Products : cppncss- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000107
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure p... Read more
Affected Products : job_and_node_ownership- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1000106
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenk... Read more
Affected Products : gerrit_trigger- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1000105
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information... Read more
Affected Products : gerrit_trigger- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000104
A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) t... Read more
Affected Products : coverity- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000101
Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appea... Read more
Affected Products : mingw-w64- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000100
GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplie... Read more
- Published: Mar. 06, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000099
Teluu PJSIP version 2.7.1 and earlier contains a Access of Null/Uninitialized Pointer vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears t... Read more
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000098
Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in... Read more
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000097
Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can resul... Read more
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-1000096
brianleroux tiny-json-http version all versions since commit 9b8e74a232bba4701844e07bcba794173b0238a8 (Oct 29 2016) contains a Missing SSL certificate validation vulnerability in The libraries core functionality is affected. that can result in Exposes the... Read more
Affected Products : tiny-json-http- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1000095
oVirt version 4.2.0 to 4.2.2 contains a Cross Site Scripting (XSS) vulnerability in the name/description of VMs portion of the web admin application. This vulnerability appears to have been fixed in version 4.2.3.... Read more
Affected Products : ovirt-engine- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-1000094
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File ... Read more
Affected Products : cms_made_simple- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000093
CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution an... Read more
Affected Products : cryptonote- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000092
CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A spe... Read more
Affected Products : cms_made_simple- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000091
KadNode version version 2.2.0 contains a Buffer Overflow vulnerability in Arguments when starting up the binary that can result in Control of program execution flow, leading to remote code execution.... Read more
Affected Products : kadnode- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000090
textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a sp... Read more
Affected Products : textpattern- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2018-1000089
Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to b... Read more
Affected Products : django-anymail- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-1000088
Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will ... Read more
Affected Products : doorkeeper- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024