|
281651
|
- |
|
jenkins
|
jenkins
|
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vector…
|
CWE-200
Information Exposure
|
CVE-2014-2064
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281652
|
- |
|
jenkins
|
jenkins
|
Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2014-2063
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281653
|
- |
|
jenkins
|
jenkins
|
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
|
CWE-287
Improper Authentication
|
CVE-2014-2062
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281654
|
- |
|
jenkins
|
jenkins
|
The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default val…
|
CWE-310
Cryptographic Issues
|
CVE-2014-2061
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281655
|
- |
|
jenkins
|
jenkins
|
The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2014-2060
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281656
|
- |
|
jenkins
|
jenkins
|
BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOT…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2058
|
2024-11-21 11:05 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281657
|
- |
|
vbulletin
|
vbulletin
|
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the conc…
|
CWE-89
SQL Injection
|
CVE-2014-2022
|
2024-11-21 11:05 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281658
|
- |
|
opensuse python
|
opensuse requests
|
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.
|
CWE-200
Information Exposure
|
CVE-2014-1830
|
2024-11-21 11:05 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281659
|
- |
|
debian python canonical mageia
|
debian_linux requests ubuntu_linux mageia
|
Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.
|
CWE-200
Information Exposure
|
CVE-2014-1829
|
2024-11-21 11:05 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281660
|
- |
|
owncloud
|
owncloud
|
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote authenticated users to bypass intended access restrictions, upload files with arbi…
|
CWE-94
Code Injection
|
CVE-2014-2044
|
2024-11-21 11:05 |
2014-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|