|
248521
|
6.5 |
MEDIUM
Network
|
jenkins
|
copy_to_slave
|
An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jo…
|
CWE-200
Information Exposure
|
CVE-2018-1000148
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248522
|
6.5 |
MEDIUM
Network
|
perforce
|
perforce
|
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to o…
|
CWE-200
Information Exposure
|
CVE-2018-1000147
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248523
|
8.8 |
HIGH
Network
|
jenkins
|
liquibase_runner
|
An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the…
|
NVD-CWE-noinfo
|
CVE-2018-1000146
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248524
|
6.5 |
MEDIUM
Network
|
jenkins
|
perforce
|
An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to …
|
CWE-200
Information Exposure
|
CVE-2018-1000145
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248525
|
6.1 |
MEDIUM
Network
|
jenkins
|
cucumber_living_documentation
|
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000144
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248526
|
6.7 |
MEDIUM
Local
|
jenkins
|
github_pull_request_builder
|
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system acce…
|
CWE-200
Information Exposure
|
CVE-2018-1000143
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248527
|
7.8 |
HIGH
Local
|
jenkins
|
github_pull_request_builder
|
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system acce…
|
CWE-200
Information Exposure
|
CVE-2018-1000142
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248528
|
8.8 |
HIGH
Network
|
microsoft
|
security_essentials exchange_server forefront_endpoint_protection_2010 intune_endpoint_protection system_center_endpoint_protection windows_defender
|
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protect…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-0986
|
2024-11-21 12:39 |
2018-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248529
|
9.1 |
CRITICAL
Network
|
i-librarian
|
i_librarian
|
I, Librarian version 4.9 and earlier contains an Incorrect Access Control vulnerability in ajaxdiscussion.php that can result in any users gaining unauthorized access (read, write and delete) to proj…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000141
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248530
|
9.8 |
CRITICAL
Network
|
rsyslog debian canonical redhat
|
librelp debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterpr…
|
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000140
|
2024-11-21 12:39 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|