Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 55 250

Количество 55 250

redhat логотип

CVE-2018-1999005

около 8 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2018-1999004

около 8 лет назад

A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-1999003

около 8 лет назад

A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

CVSS3: 4.6
EPSS: Низкий
redhat логотип

CVE-2018-1999002

около 8 лет назад

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.

CVSS3: 7.5
EPSS: Высокий
redhat логотип

CVE-2018-1999001

около 8 лет назад

A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.

CVSS3: 8.8
EPSS: Средний
redhat логотип

CVE-2018-19985

больше 7 лет назад

The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.

CVSS3: 4.6
EPSS: Низкий
redhat логотип

CVE-2018-19967

почти 8 лет назад

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2018-19966

почти 8 лет назад

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2018-19965

почти 8 лет назад

An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-19964

почти 8 лет назад

An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-19963

почти 8 лет назад

An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2018-19962

почти 8 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2018-19961

почти 8 лет назад

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2018-19935

почти 8 лет назад

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-19932

больше 7 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19931

больше 7 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19876

почти 8 лет назад

cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-19873

больше 7 лет назад

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2018-19872

больше 7 лет назад

An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2018-19871

около 8 лет назад

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-1999005

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

CVSS3: 6.4
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1999004

A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in SlaveComputer.java that allows attackers with Overall/Read permission to initiate agent launches, and abort in-progress agent launches.

CVSS3: 5.3
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1999003

A Improper authorization vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in Queue.java that allows attackers with Overall/Read permission to cancel queued builds.

CVSS3: 4.6
1%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-1999002

A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers to send crafted HTTP requests returning the contents of any file on the Jenkins master file system that the Jenkins master has access to.

CVSS3: 7.5
87%
Высокий
около 8 лет назад
redhat логотип
CVE-2018-1999001

A unauthorized modification of configuration vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in User.java that allows attackers to provide crafted login credentials that cause Jenkins to move the config.xml file from the Jenkins home directory. If Jenkins is started without this file present, it will revert to the legacy defaults of granting administrator access to anonymous users.

CVSS3: 8.8
18%
Средний
около 8 лет назад
redhat логотип
CVE-2018-19985

The function hso_get_config_data in drivers/net/usb/hso.c in the Linux kernel through 4.19.8 reads if_num from the USB device (as a u8) and uses it to index a small array, resulting in an object out-of-bounds (OOB) read that potentially allows arbitrary read in the kernel address space.

CVSS3: 4.6
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-19967

An issue was discovered in Xen through 4.11.x on Intel x86 platforms allowing guest OS users to cause a denial of service (host OS hang) because Xen does not work around Intel's mishandling of certain HLE transactions associated with the KACQUIRE instruction prefix.

CVSS3: 5.3
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19966

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

CVSS3: 5.1
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19965

An issue was discovered in Xen through 4.11.x allowing 64-bit PV guest OS users to cause a denial of service (host OS crash) because #GP[0] can occur after a non-canonical address is passed to the TLB flushing code. NOTE: this issue exists because of an incorrect CVE-2017-5754 (aka Meltdown) mitigation.

CVSS3: 5.9
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19964

An issue was discovered in Xen 4.11.x allowing x86 guest OS users to cause a denial of service (host OS hang) because the p2m lock remains unavailable indefinitely in certain error conditions.

CVSS3: 5.9
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19963

An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because x86 IOREQ server resource accounting (for external emulators) was mishandled.

CVSS3: 5.1
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19962

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because small IOMMU mappings are unsafely combined into larger ones.

CVSS3: 8.1
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19961

An issue was discovered in Xen through 4.11.x on AMD x86 platforms, possibly allowing guest OS users to gain host OS privileges because TLB flushes do not always occur after IOMMU mapping changes.

CVSS3: 8.1
0%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19935

ext/imap/php_imap.c in PHP 5.x and 7.x before 7.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an empty string in the message argument to the imap_mail function.

CVSS3: 5.9
6%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19932

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

CVSS3: 3.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-19931

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.

CVSS3: 3.3
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-19876

cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid pointer" error.

CVSS3: 5.9
2%
Низкий
почти 8 лет назад
redhat логотип
CVE-2018-19873

An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.

CVSS3: 3.3
3%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-19872

An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.

CVSS3: 6.2
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-19871

An issue was discovered in Qt before 5.11.3. There is QTgaFile Uncontrolled Resource Consumption.

CVSS3: 3.3
2%
Низкий
около 8 лет назад

Уязвимостей на страницу