|
248401
|
7.5 |
HIGH
Network
|
rubygems debian
|
rubygems debian_linux
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-1000075
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248402
|
7.8 |
HIGH
Local
|
rubygems
|
rubygems
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000074
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248403
|
7.5 |
HIGH
Network
|
rubygems
|
rubygems
|
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains…
|
CWE-59
Link Following
|
CVE-2018-1000073
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248404
|
7.5 |
HIGH
Network
|
iredmail
|
iredmail
|
iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other imp…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000072
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248405
|
7.5 |
HIGH
Network
|
roundcube
|
webmail
|
roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via networ…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000071
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248406
|
5.5 |
MEDIUM
Local
|
freeplane debian
|
freeplane debian_linux
|
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to r…
|
CWE-611
XXE
|
CVE-2018-1000069
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248407
|
8.8 |
HIGH
Network
|
bitmessage
|
pybitmessage
|
Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file src/messagetypes/__in…
|
CWE-94
Code Injection
|
CVE-2018-1000070
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248408
|
4.3 |
MEDIUM
Network
|
jenkins
|
promoted_builds
|
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform …
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000114
|
2024-11-21 12:39 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248409
|
5.4 |
MEDIUM
Network
|
jenkins
|
testlink
|
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report nam…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000113
|
2024-11-21 12:39 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248410
|
5.3 |
MEDIUM
Network
|
jenkins
|
mercurial
|
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and us…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000112
|
2024-11-21 12:39 |
2018-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|