Unknown · CVSS Not scored
A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Bitbucket Approve Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins VS Team Services Continuous Deployment Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins veracode-scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins aws-device-farm Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins WebSphere Deployer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Official OWASP ZAP Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins VMware vRealize Automation Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins OctopusDeploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Aqua Security Scanner Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins AWS CloudWatch Logs Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Jenkins Bugzilla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Published Apr 4, 2019 · Updated Aug 5, 2024
Medium · CVSS 6.5
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Published Apr 1, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Published Apr 25, 2022 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.
Published Apr 6, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published Apr 27, 2021 · Updated Aug 5, 2024
Medium · CVSS 6.8
Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects DGN2200v4 before 1.0.0.110 and DGND2200Bv4 before 1.0.0.109.
Published Apr 16, 2020 · Updated Aug 5, 2024
Medium · CVSS 5.2
NETGEAR WAC510 devices before 8.0.1.3 are affected by stored XSS.
Published Apr 16, 2020 · Updated Aug 5, 2024
Medium · CVSS 4.3
Certain NETGEAR devices are affected by reflected XSS. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7800 before 1.0.2.58, R8900 before 1.0.4.12, R9000 before 1.0.4.8, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN3000RPv2 before 1.0.0.68, WN3000RPv3 before 1.0.2.70, WN3100RPv2 before 1.0.0.60, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.68.
Published Apr 16, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Croogo before 3.0.7 allows XSS via the title to admin/menus/menus or admin/taxonomy/vocabularies.
Published Apr 26, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService mishandles OTA Provisioning on V40 and G7 devices. The LG ID is LVE-SMP-190006 (July 2019).
Published Apr 17, 2020 · Updated Aug 5, 2024
Medium · CVSS 6.8
NETGEAR R7800 devices before 1.0.2.52 are affected by a stack-based buffer overflow by an authenticated user.
Published Apr 16, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690.
Published Apr 23, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
Published Apr 27, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).
Published Apr 17, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
handleIncomingPacket in conn.go in Pion DTLS before 1.5.2 lacks a check for application data with epoch 0, which allows remote attackers to inject arbitrary unencrypted data after handshake completion.
Published Apr 19, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).
Published Apr 17, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).
Published Apr 17, 2020 · Updated Aug 5, 2024
Medium · CVSS 4.8
Certain NETGEAR devices are affected by stored XSS. This affects D3600 before 1.0.0.75, D6000 before 1.0.0.75, D7800 before 1.0.1.44, DM200 before 1.0.0.58, R7800 before 1.0.2.58, R8900 before 1.0.4.12, R9000 before 1.0.4.12, RBK20 before 2.3.0.28, RBR20 before 2.3.0.28, RBS20 before 2.3.0.28, RBK40 before 2.3.0.28, RBS40 before 2.3.0.28, RBK50 before 2.3.0.32, RBR50 before 2.3.0.32, RBS50 before 2.3.0.32, WN3000RPv2 before 1.0.0.68, WN3000RPv3 before 1.0.2.70, WN3100RPv2 before 1.0.0.60, WNDR4300v2 before 1.0.0.58, WNDR4500v3 before 1.0.0.58, and WNR2000v5 before 1.0.0.68.
Published Apr 16, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
OpenThread before 2019-12-13 has a stack-based buffer overflow in MeshCoP::Commissioner::GeneratePskc.
Published Apr 28, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Teeworlds before 0.7.4 has an integer overflow when computing a tilemap size.
Published Apr 22, 2020 · Updated Aug 5, 2024
High · CVSS 7.6
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
Published Apr 16, 2020 · Updated Aug 5, 2024