|
248271
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_7 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve information that could lead to a Kernel Address Space Layout Randomization (ASLR) bypass,…
|
NVD-CWE-noinfo
|
CVE-2018-0968
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248272
|
5.3 |
MEDIUM
Network
|
microsoft
|
windows_server_2012 windows_10 windows_server_2016 windows_8.1 windows_server_2008 windows_7 windows_rt_8.1
|
A denial of service vulnerability exists in the way that Windows SNMP Service handles malformed SNMP traps, aka "Windows SNMP Service Denial of Service Vulnerability." This affects Windows 7, Windows…
|
NVD-CWE-noinfo
|
CVE-2018-0967
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248273
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_7 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows…
|
NVD-CWE-noinfo
|
CVE-2018-0960
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248274
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_server_2008 windows_server_2016 windows_10 windows_7 windows_8.1 windows_rt_8.1
|
An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7…
|
CWE-665
Improper Initialization
|
CVE-2018-0887
|
2024-11-21 12:39 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248275
|
7.8 |
HIGH
Local
|
gnu canonical debian redhat
|
patch ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterpris…
|
GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear …
|
CWE-20
Improper Input Validation
|
CVE-2018-1000156
|
2024-11-21 12:39 |
2018-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248276
|
6.1 |
MEDIUM
Network
|
zammad
|
zammad
|
Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000154
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248277
|
8.8 |
HIGH
Network
|
jenkins
|
vsphere
|
A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSna…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000153
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248278
|
6.3 |
MEDIUM
Network
|
jenkins
|
vsphere
|
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapsh…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000152
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248279
|
5.6 |
MEDIUM
Network
|
jenkins
|
vsphere
|
A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-1000151
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248280
|
3.3 |
LOW
Local
|
jenkins
|
reverse_proxy_auth
|
An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system acce…
|
CWE-200
Information Exposure
|
CVE-2018-1000150
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|