Show filters
174 Total Results
Displaying 81-90 of 174
Sort by:
Attacker Value
Unknown

CVE-2018-1000186

Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown

CVE-2017-16026

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
0
Attacker Value
Unknown

CVE-2018-1000143

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
0
Attacker Value
Unknown

CVE-2018-1000142

Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
0
Attacker Value
Unknown

CVE-2015-5016

Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown

CVE-2015-9257

Disclosure Date: March 24, 2018 (last updated November 26, 2024)
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
0
Attacker Value
Unknown

CVE-2017-18228

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
0
Attacker Value
Unknown

CVE-2017-18223

Disclosure Date: March 10, 2018 (last updated November 26, 2024)
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
0
Attacker Value
Unknown

CVE-2017-5943

Disclosure Date: July 03, 2017 (last updated November 26, 2024)
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.
0
Attacker Value
Unknown

CVE-2016-6127

Disclosure Date: July 03, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.
0