Show filters
501 Total Results
Displaying 241-250 of 501
Sort by:
Attacker Value
Unknown

CVE-2019-10409

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.
Attacker Value
Unknown

CVE-2019-10408

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.
Attacker Value
Unknown

CVE-2019-10407

Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
Attacker Value
Unknown

CVE-2019-1264

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
A security feature bypass vulnerability exists when Microsoft Office improperly handles input, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Attacker Value
Unknown

CVE-2019-1231

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
An information disclosure vulnerability exists in the way Rome SDK handles server SSL/TLS certificate validation, aka 'Rome SDK Information Disclosure Vulnerability'.
Attacker Value
Unknown

CVE-2019-15496

Disclosure Date: August 28, 2019 (last updated November 27, 2024)
MyT Project Management 1.5.1 lacks CSRF protection and, for example, allows a user/create CSRF attack. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
0
Attacker Value
Unknown

CVE-2019-2831

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
Vulnerability in the PeopleSoft Enterprise FIN Project Costing component of Oracle PeopleSoft Products (subcomponent: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Project Costing. While the vulnerability is in PeopleSoft Enterprise FIN Project Costing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Project Costing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Project Costing. CVSS 3.0 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L).
0
Attacker Value
Unknown

CVE-2019-1036

Disclosure Date: June 12, 2019 (last updated November 27, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-1031, CVE-2019-1032, CVE-2019-1033.
0
Attacker Value
Unknown

CVE-2019-1033

Disclosure Date: June 12, 2019 (last updated November 27, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-1031, CVE-2019-1032, CVE-2019-1036.
0
Attacker Value
Unknown

CVE-2019-1031

Disclosure Date: June 12, 2019 (last updated November 27, 2024)
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-1032, CVE-2019-1033, CVE-2019-1036.
0