Show filters
813 Total Results
Displaying 431-440 of 813
Sort by:
Attacker Value
Unknown

CVE-2018-20990

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
An issue was discovered in the tar crate before 0.4.16 for Rust. Arbitrary file overwrite can occur via a symlink or hardlink in a TAR archive.
0
Attacker Value
Unknown

CVE-2019-10377

Disclosure Date: August 07, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins.
Attacker Value
Unknown

CVE-2019-1869

Disclosure Date: June 19, 2019 (last updated November 27, 2024)
A vulnerability in the internal packet-processing functionality of the Cisco StarOS operating system running on virtual platforms could allow an unauthenticated, remote attacker to cause an affected device to stop processing traffic, resulting in a denial of service (DoS) condition. The vulnerability is due to a logic error that may occur under specific traffic conditions. An attacker could exploit this vulnerability by sending a series of crafted packets to an affected device. A successful exploit could allow the attacker to prevent the targeted service interface from receiving any traffic, which would lead to a DoS condition on the affected interface. The device may have to be manually reloaded to recover from exploitation of this vulnerability.
0
Attacker Value
Unknown

CVE-2019-10998

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.
0
Attacker Value
Unknown

CVE-2019-10997

Disclosure Date: June 17, 2019 (last updated November 27, 2024)
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually via a Linux shell.
0
Attacker Value
Unknown

CVE-2018-20834

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
0
Attacker Value
Unknown

CVE-2018-20835

Disclosure Date: April 30, 2019 (last updated November 27, 2024)
A vulnerability was found in tar-fs before 1.16.2. An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.
0
Attacker Value
Unknown

CVE-2019-10277

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Attacker Value
Unknown

CVE-2019-9923

Disclosure Date: March 22, 2019 (last updated November 08, 2023)
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers.
0
Attacker Value
Unknown

CVE-2018-20026

Disclosure Date: February 19, 2019 (last updated November 27, 2024)
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.