|
199401
|
8.1 |
HIGH
Network
|
jenkins
|
jenkins
|
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after…
|
CWE-352
Origin Validation Error
|
CVE-2017-1000504
|
2024-11-21 12:04 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199402
|
8.1 |
HIGH
Network
|
jenkins
|
jenkins
|
A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failur…
|
CWE-362
Race Condition
|
CVE-2017-1000503
|
2024-11-21 12:04 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199403
|
8.8 |
HIGH
Network
|
jenkins
|
ec2
|
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be l…
|
CWE-78
OS Command
|
CVE-2017-1000502
|
2024-11-21 12:04 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199404
|
9.8 |
CRITICAL
Network
|
vehicle_sales_management_system_project
|
vehicle_sales_management_system
|
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and …
|
CWE-89
SQL Injection
|
CVE-2017-1000474
|
2024-11-21 12:04 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199405
|
7.8 |
HIGH
Local
|
freesshd
|
freesshd
|
FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.
|
CWE-428
Unquoted Search Path or Element
|
CVE-2017-1000475
|
2024-11-21 12:04 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199406
|
5.3 |
MEDIUM
Network
|
matrixssl
|
matrixssl
|
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-1000417
|
2024-11-21 12:04 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199407
|
5.3 |
MEDIUM
Network
|
axtls_project
|
axtls
|
axTLS version 1.5.3 has a coding error in the ASN.1 parser resulting in the year (19)50 of UTCTime being misinterpreted as 2050.
|
CWE-193
Off-by-one Error
|
CVE-2017-1000416
|
2024-11-21 12:04 |
2018-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199408
|
6.1 |
MEDIUM
Network
|
flatcore
|
flatcore-cms
|
flatCore-CMS 1.4.6 is vulnerable to reflected XSS in user_management.php due to the use of $_SERVER['PHP_SELF'] to build links and a stored XSS in the admin log panel by specifying a malformed User-A…
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000428
|
2024-11-21 12:04 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199409
|
5.4 |
MEDIUM
Network
|
sulu
|
sulu-standard
|
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000465
|
2024-11-21 12:04 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199410
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000429
|
2024-11-21 12:04 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|