|
248171
|
7.8 |
HIGH
Local
|
ruby-ffi_project
|
ruby-ffi
|
ruby-ffi version 1.9.23 and earlier has a DLL loading issue which can be hijacked on Windows OS, when a Symbol is used as DLL name instead of a String This vulnerability appears to have been fixed in…
|
CWE-426
Untrusted Search Path
|
CVE-2018-1000201
|
2024-11-21 12:39 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248172
|
7.0 |
HIGH
Local
|
microsoft
|
windows_server_2016 windows_10
|
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windo…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-0982
|
2024-11-21 12:39 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248173
|
7.5 |
HIGH
Network
|
microsoft
|
internet_explorer
|
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This affects Internet Explorer 9, I…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0978
|
2024-11-21 12:39 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248174
|
4.3 |
MEDIUM
Network
|
microsoft
|
edge
|
An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE…
|
CWE-200
Information Exposure
|
CVE-2018-0871
|
2024-11-21 12:39 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248175
|
7.5 |
HIGH
Network
|
soarlabs
|
soarcoin
|
Soar Labs Soar Coin version up to and including git commit 4a2aa71ee21014e2880a3f7aad11091ed6ad434f (latest release as of Sept 2017) contains an intentional backdoor vulnerability in the function zer…
|
NVD-CWE-noinfo
|
CVE-2018-1000203
|
2024-11-21 12:39 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248176
|
5.4 |
MEDIUM
Network
|
jenkins
|
groovy_postbuild
|
A persisted cross-site scripting vulnerability exists in Jenkins Groovy Postbuild Plugin 2.3.1 and older in various Jelly files that allows attackers able to control build badge content to define Jav…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000202
|
2024-11-21 12:39 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248177
|
6.5 |
MEDIUM
Network
|
jenkins
|
black_duck_hub
|
A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read permission to make Jenki…
|
CWE-611
XXE
|
CVE-2018-1000198
|
2024-11-21 12:39 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248178
|
8.1 |
HIGH
Network
|
jenkins
|
black_duck_hub
|
An improper authorization vulnerability exists in Jenkins Black Duck Hub Plugin 3.0.3 and older in PostBuildScanDescriptor.java that allows users with Overall/Read permission to read and write the Bl…
|
CWE-863
Incorrect Authorization
|
CVE-2018-1000197
|
2024-11-21 12:39 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248179
|
6.5 |
MEDIUM
Network
|
jenkins
|
gitlab_hook
|
A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins…
|
CWE-200
Information Exposure
|
CVE-2018-1000196
|
2024-11-21 12:39 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248180
|
4.3 |
MEDIUM
Network
|
jenkins oracle
|
jenkins communications_cloud_native_core_automated_test_suite
|
A server-side request forgery vulnerability exists in Jenkins 2.120 and older, LTS 2.107.2 and older in ZipExtractionInstaller.java that allows users with Overall/Read permission to have Jenkins subm…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000195
|
2024-11-21 12:39 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|