|
247311
|
8.8 |
HIGH
Network
|
microsoft
|
windows_server_2008 windows_server_2012 windows_8.1 windows_server_2016 windows_7 windows_rt_8.1 windows_server_1803 windows_10_1703 windows_10_1709 windows_10_1803 wind…
|
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." T…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-0824
|
2024-11-21 12:39 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247312
|
7.5 |
HIGH
Network
|
quassel-irc debian
|
quassel debian_linux
|
A NULL Pointer Dereference of CWE-476 exists in quassel version 0.12.4 in the quasselcore void CoreAuthHandler::handle(const Login &msg) coreauthhandler.cpp line 235 that allows an attacker to cause …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-1000179
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247313
|
9.8 |
CRITICAL
Network
|
quassel-irc debian
|
quassel debian_linux
|
A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datastreampeer.cpp line 62 that allows an attacker to e…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-1000178
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247314
|
5.4 |
MEDIUM
Network
|
jenkins
|
s3_publisher
|
A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000177
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247315
|
6.5 |
MEDIUM
Network
|
jenkins
|
email_extension
|
An exposure of sensitive information vulnerability exists in Jenkins Email Extension Plugin 2.61 and older in src/main/resources/hudson/plugins/emailext/ExtendedEmailPublisher/global.groovy and Exten…
|
CWE-200
Information Exposure
|
CVE-2018-1000176
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247316
|
6.5 |
MEDIUM
Network
|
jenkins
|
html_publisher
|
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arb…
|
CWE-22
Path Traversal
|
CVE-2018-1000175
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247317
|
6.1 |
MEDIUM
Network
|
jenkins
|
google_login
|
An open redirect vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows attackers to redirect users to an arbitrary URL after successful login.
|
CWE-601
Open Redirect
|
CVE-2018-1000174
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247318
|
5.9 |
MEDIUM
Network
|
jenkins
|
google_login
|
A session fixaction vulnerability exists in Jenkins Google Login Plugin 1.3 and older in GoogleOAuth2SecurityRealm.java that allows unauthorized attackers to impersonate another user if they can cont…
|
CWE-384
Session Fixation
|
CVE-2018-1000173
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247319
|
7.5 |
HIGH
Network
|
nghttp2 nodejs debian
|
nghttp2 node.js debian_linux
|
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service…
|
CWE-20 CWE-476
Improper Input Validation NULL Pointer Dereference
|
CVE-2018-1000168
|
2024-11-21 12:39 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247320
|
4.8 |
MEDIUM
Network
|
imagely
|
nextgen_gallery
|
Imagely NextGEN Gallery version 2.2.30 and earlier contains a Cross Site Scripting (XSS) vulnerability in Image Alt & Title Text. This attack appears to be exploitable via a victim viewing the image …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000172
|
2024-11-21 12:39 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|