Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 892

Количество 55 892

redhat логотип

CVE-2020-21533

больше 6 лет назад

fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21532

больше 6 лет назад

fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21531

больше 6 лет назад

fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21530

больше 6 лет назад

fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-2152

больше 6 лет назад

Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2020-21529

больше 6 лет назад

fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21528

больше 6 лет назад

A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2020-21514

больше 3 лет назад

An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-21490

больше 6 лет назад

An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.

EPSS: Низкий
redhat логотип

CVE-2020-21469

около 3 лет назад

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2020-21468

почти 5 лет назад

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2020-2139

больше 6 лет назад

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2020-2138

больше 6 лет назад

Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2136

больше 6 лет назад

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2135

больше 6 лет назад

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-2134

больше 6 лет назад

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-2111

больше 6 лет назад

Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2020-2110

больше 6 лет назад

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-2109

больше 6 лет назад

Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-2105

больше 6 лет назад

REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

CVSS3: 3.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2020-21533

fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21532

fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21531

fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21530

fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2152

Jenkins Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21529

fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21528

A Segmentation Fault issue discovered in in ieee_segment function in outieee.c in nasm 2.14.03 and 2.15 allows remote attackers to cause a denial of service via crafted assembly file.

CVSS3: 5.5
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21514

An issue was discovered in Fluent-ui v.1.2.2 allows attackers to gain escalated privileges and execute arbitrary code due to a default password.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2020-21490

An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled.

0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-21469

An issue was discovered in PostgreSQL 12.2 allows attackers to cause a denial of service via repeatedly sending SIGHUP signals. NOTE: this is disputed by the vendor because untrusted users cannot send SIGHUP signals; they can only be sent by a PostgreSQL superuser, a user with pg_reload_conf access, or a user with sufficient privileges at the OS level (the postgres account or the root account).

CVSS3: 4.4
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2020-21468

A segmentation fault in the redis-server component of Redis 5.0.7 leads to a denial of service (DOS). NOTE: the vendor cannot reproduce this issue in a released version, such as 5.0.7.

CVSS3: 7.5
1%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-2139

An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.

CVSS3: 6.5
2%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2138

Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2136

Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2135

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted method calls on objects that implement GroovyInterceptable.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2134

Sandbox protection in Jenkins Script Security Plugin 1.70 and earlier could be circumvented through crafted constructor calls and crafted constructor bodies.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2111

Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2110

Sandbox protection in Jenkins Script Security Plugin 1.69 and earlier could be circumvented during the script compilation phase by applying AST transforming annotations to imports or by using them inside of other annotations.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2109

Sandbox protection in Jenkins Pipeline: Groovy Plugin 2.78 and earlier can be circumvented through default parameter expressions in CPS-transformed methods.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-2105

REST API endpoints in Jenkins 2.218 and earlier, LTS 2.204.1 and earlier were vulnerable to clickjacking attacks.

CVSS3: 3.1
2%
Низкий
больше 6 лет назад

Уязвимостей на страницу