|
246831
|
8.8 |
HIGH
Network
|
jenkins
|
pipeline_supporting_apis
|
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented i…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000058
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246832
|
8.3 |
HIGH
Network
|
jenkins
|
junit
|
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the …
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2018-1000056
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246833
|
8.3 |
HIGH
Network
|
jenkins
|
android_lint
|
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets fro…
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2018-1000055
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246834
|
8.3 |
HIGH
Network
|
jenkins
|
ccm
|
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jen…
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2018-1000054
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246835
|
8.8 |
HIGH
Network
|
limesurvey
|
limesurvey
|
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, r…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000053
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246836
|
7.5 |
HIGH
Network
|
fmt
|
fmt
|
fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corruption (SIGSEGV), CWE-134 vulnerability in fmt::print() library function that can …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2018-1000052
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246837
|
7.8 |
HIGH
Local
|
artifex debian
|
mupdf debian_linux
|
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a …
|
CWE-416
Use After Free
|
CVE-2018-1000051
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246838
|
8.8 |
HIGH
Network
|
stb_vorbis_project
|
stb_vorbis
|
Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-1000050
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246839
|
7.5 |
HIGH
Network
|
nanopool
|
claymore_dual_miner
|
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/writ…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000049
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246840
|
8.8 |
HIGH
Network
|
nasa
|
rtretrievalframework
|
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exp…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000048
|
2024-11-21 12:39 |
2018-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|