|
199591
|
5.4 |
MEDIUM
Network
|
pluxml
|
pluxml
|
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.
|
CWE-79
Cross-site Scripting
|
CVE-2017-1001001
|
2024-11-21 12:04 |
2017-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199592
|
9.8 |
CRITICAL
Network
|
jenkins
|
ssh
|
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-1000245
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199593
|
8.8 |
HIGH
Network
|
jenkins
|
favorite
|
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification
|
CWE-352
Origin Validation Error
|
CVE-2017-1000244
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199594
|
4.3 |
MEDIUM
Network
|
jenkins
|
favorite_plugin
|
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites
|
CWE-862
Missing Authorization
|
CVE-2017-1000243
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199595
|
3.3 |
LOW
Local
|
jenkins
|
git_client
|
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure
|
CWE-200
Information Exposure
|
CVE-2017-1000242
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199596
|
5.5 |
MEDIUM
Local
|
gnu
|
emacs
|
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible…
|
CWE-200
Information Exposure
|
CVE-2017-1000383
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199597
|
5.5 |
MEDIUM
Local
|
vim
|
vim
|
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways…
|
CWE-200
Information Exposure
|
CVE-2017-1000382
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199598
|
9.1 |
CRITICAL
Network
|
haxx debian
|
libcurl debian_linux
|
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000257
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199599
|
8.1 |
HIGH
Network
|
redhat debian
|
libvirt debian_linux
|
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-1000256
|
2024-11-21 12:04 |
2017-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199600
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn so that the kernel will take an exception (interrupt), and use the r1 value *fro…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000255
|
2024-11-21 12:04 |
2017-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|