CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2019-1003081

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

    Published: 4 Apr 2019
    6.5
    Medium

    CVE-2019-1003082

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.

    Published: 4 Apr 2019
    6.5
    Medium

    CVE-2019-1003079

    Last Modified: 21 Nov 2024

    A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003074

    Last Modified: 21 Nov 2024

    Jenkins Hyper.sh Commons Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003061

    Last Modified: 21 Nov 2024

    Jenkins jenkins-cloudformation-plugin Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003067

    Last Modified: 21 Nov 2024

    Jenkins Trac Publisher Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003051

    Last Modified: 21 Nov 2024

    Jenkins IRC Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003052

    Last Modified: 21 Nov 2024

    Jenkins AWS Elastic Beanstalk Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003054

    Last Modified: 21 Nov 2024

    Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003055

    Last Modified: 21 Nov 2024

    Jenkins FTP publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2019-1003053

    Last Modified: 21 Nov 2024

    Jenkins HockeyApp Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

    Published: 4 Apr 2019
    4.3
    Medium

    CVE-2019-10273

    Last Modified: 21 Nov 2024

    Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticated users to enumerate active users. Due to a flaw within the way the authentication is handled, an attacker is able to login and verify any active account.

    Published: 4 Apr 2019
    5.9
    Medium

    CVE-2019-1828

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices use weak encryption algorithms for user credentials. An attacker could exploit this vulnerability by conducting a man-in-the-middle attack and decrypting intercepted credentials. A successful exploit could allow the attacker to gain access to an affected device with administrator privileges. This vulnerability affects Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers running firmware releases prior to 1.4.2.22.

    Published: 4 Apr 2019
    6.1
    Medium

    CVE-2019-1827

    Last Modified: 21 Nov 2024

    A vulnerability in the Online Help web service of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the service. The vulnerability exists because the Online Help web service of an affected device insufficiently validates user-supplied input. An attacker could exploit this vulnerability by persuading a user of the service to click a malicious link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected service or access sensitive browser-based information.This vulnerability affects Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers running firmware releases prior to 1.4.2.22.

    Published: 4 Apr 2019
    9.8
    Critical

    CVE-2018-10243

    Last Modified: 21 Nov 2024

    htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.

    Published: 4 Apr 2019
    5.5
    Medium

    CVE-2018-11958

    Last Modified: 21 Nov 2024

    Insufficient protection of keys in keypad can lead HLOS to gain access to confidential keypad input data in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9206, MDM9607, MDM9650, MDM9655, Qualcomm 215, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016

    Published: 4 Apr 2019
    7.8
    High

    CVE-2018-11830

    Last Modified: 21 Nov 2024

    Improper input validation in QCPE create function may lead to integer overflow in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, SD 410/12, SD 820A

    Published: 4 Apr 2019
    7.8
    High

    CVE-2018-11966

    Last Modified: 21 Nov 2024

    Undefined behavior in UE while processing unknown IEI in OTA message in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660, SDX20, SM7150, Snapdragon_High_Med_2016, SXR1130

    Published: 4 Apr 2019
    7.8
    High

    CVE-2018-11970

    Last Modified: 21 Nov 2024

    TZ App dynamic allocations not protected from XBL loader in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130

    Published: 4 Apr 2019
    5.5
    Medium

    CVE-2018-11971

    Last Modified: 21 Nov 2024

    Interrupt exit code flow may undermine access control policy set forth by secure world can lead to potential secure asset leakage in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, in MDM9206, MDM9607, MDM9650, MDM9655, QCS605, SD 410/12, SD 615/16/SD 415, SD 636, SD 712 / SD 710 / SD 670, SD 845 / SD 850, SD 8CX, SDA660, SDM630, SDM660, SXR1130

    Published: 4 Apr 2019
    7.8
    High

    CVE-2018-13918

    Last Modified: 21 Nov 2024

    kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent operation and stops normal operation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 675, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDX24, SM7150

    Published: 4 Apr 2019
    9.8
    Critical

    CVE-2018-10244

    Last Modified: 21 Nov 2024

    Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.

    Published: 4 Apr 2019
    —
    Unknown

    CVE-2019-5022

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: this candidate is not about any specific product, protocol, or design, that falls into the scope of the assigning CNA. Notes: None

    Published: 4 Apr 2019
    7.5
    High

    CVE-2018-10242

    Last Modified: 21 Nov 2024

    Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

    Published: 4 Apr 2019
    7.2
    High

    CVE-2018-19981

    Last Modified: 21 Nov 2024

    Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated and/or authorized requests. Note that the attacker must have "root" privilege access to the Android filesystem in order to exploit this vulnerability (i.e. the device has been compromised, such as disabling or bypassing Android's fundamental security mechanisms).

    Published: 4 Apr 2019
    9.8
    Critical

    CVE-2019-10844

    Last Modified: 21 Nov 2024

    nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which might be untrusted.

    Published: 4 Apr 2019
    3.3
    Low

    CVE-2019-3892

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-11599. Reason: This candidate is a reservation duplicate of CVE-2019-11599. Notes: All CVE users should reference CVE-2019-11599 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 4 Apr 2019
    8.8
    High

    CVE-2015-5384

    Last Modified: 21 Nov 2024

    AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier is vulnerable to a Session Fixation attack.

    Published: 3 Apr 2019
    6.1
    Medium

    CVE-2015-5462

    Last Modified: 21 Nov 2024

    AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.

    Published: 3 Apr 2019
    9.8
    Critical

    CVE-2015-5463

    Last Modified: 21 Nov 2024

    AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through arbitrary SQL commands, (2) perform a horizontal and vertical privilege escalation, (3) cause a Denial of Service on global application, or (4) write/read/delete arbitrary files on server hosting the application.

    Published: 3 Apr 2019
    7.5
    High

    CVE-2015-5606

    Last Modified: 21 Nov 2024

    Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a specially crafted request.

    Published: 3 Apr 2019
    8.1
    High

    CVE-2019-10240

    Last Modified: 21 Nov 2024

    Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2017-13911

    Last Modified: 21 Nov 2024

    A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capitan 10.11.6 Security Update 2018-002, macOS Sierra 10.12.6 Security Update 2018-002, macOS High Sierra 10.13.2.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4427

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to: iOS 12.1, watchOS 5.1.2, tvOS 12.1.1, macOS High Sierra 10.13.6 Security Update 2018-003 High Sierra, macOS Sierra 10.12.6 Security Update 2018-006.

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2018-4379

    Last Modified: 21 Nov 2024

    A lock screen issue allowed access to the share function on a locked device. This issue was addressed by restricting options offered on a locked device. This issue affected versions prior to iOS 12.0.1.

    Published: 3 Apr 2019
    6.5
    Medium

    CVE-2018-4439

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved validation. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    4.3
    Medium

    CVE-2018-4440

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4441

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4442

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4443

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    3.3
    Low

    CVE-2018-4446

    Last Modified: 21 Nov 2024

    This issue was addressed with improved entitlements. This issue affected versions prior to iOS 12.1.1.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4447

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4449

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4450

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

    Published: 3 Apr 2019
    6.5
    Medium

    CVE-2018-4460

    Last Modified: 21 Nov 2024

    A denial of service issue was addressed by removing the vulnerable code. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4461

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Published: 3 Apr 2019
    5.5
    Medium

    CVE-2018-4462

    Last Modified: 21 Nov 2024

    A validation issue was addressed with improved input sanitization. This issue affected versions prior to macOS Mojave 10.14.2.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4463

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to macOS Mojave 10.14.2.

    Published: 3 Apr 2019
    8.8
    High

    CVE-2018-4464

    Last Modified: 21 Nov 2024

    Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, tvOS 12.1.1, watchOS 5.1.2, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9.

    Published: 3 Apr 2019
    7.8
    High

    CVE-2018-4465

    Last Modified: 21 Nov 2024

    A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1, macOS Mojave 10.14.2, tvOS 12.1.1, watchOS 5.1.2.

    Published: 3 Apr 2019