|
257251
|
6.5 |
MEDIUM
Network
|
mahara
|
mahara
|
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when usi…
|
CWE-613
Insufficient Session Expiration
|
CVE-2017-1000131
|
2024-11-21 12:04 |
2017-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257252
|
5.3 |
MEDIUM
Network
|
webkitgtk
|
webkitgtk\+
|
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secondary process to cause a denial of service (release…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000122
|
2024-11-21 12:04 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257253
|
9.8 |
CRITICAL
Network
|
webkitgtk
|
webkitgtk\+
|
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subse…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-1000121
|
2024-11-21 12:04 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257254
|
5.4 |
MEDIUM
Network
|
pluxml
|
pluxml
|
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1001001
|
2024-11-21 12:04 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257255
|
9.8 |
CRITICAL
Network
|
jenkins
|
ssh
|
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-1000245
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257256
|
8.8 |
HIGH
Network
|
jenkins
|
favorite
|
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
|
CWE-352
Origin Validation Error
|
CVE-2017-1000244
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257257
|
4.3 |
MEDIUM
Network
|
jenkins
|
favorite_plugin
|
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
|
CWE-862
Missing Authorization
|
CVE-2017-1000243
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257258
|
3.3 |
LOW
Local
|
jenkins
|
git_client
|
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
|
CWE-200
Information Exposure
|
CVE-2017-1000242
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257259
|
9.1 |
CRITICAL
Network
|
haxx debian
|
libcurl debian_linux
|
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000257
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257260
|
5.5 |
MEDIUM
Local
|
gnu
|
emacs
|
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible…
|
CWE-200
Information Exposure
|
CVE-2017-1000383
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|