Show filters
174 Total Results
Displaying 81-90 of 174
Sort by:
Attacker Value
Unknown
CVE-2018-1000186
Disclosure Date: June 05, 2018 (last updated November 26, 2024)
A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
0
Attacker Value
Unknown
CVE-2017-16026
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
0
Attacker Value
Unknown
CVE-2018-1000143
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
0
Attacker Value
Unknown
CVE-2018-1000142
Disclosure Date: April 05, 2018 (last updated November 26, 2024)
An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.
0
Attacker Value
Unknown
CVE-2015-5016
Disclosure Date: March 27, 2018 (last updated November 26, 2024)
IBM Maximo Asset Management 7.1, 7.5, and 7.6; Maximo Asset Management Essentials 7.1 and 7.5; Control Desk 7.5 and 7.6; Tivoli Asset Management for IT 7.1 and 7.2; and certain other IBM products allow remote authenticated users to bypass intended access restrictions and read arbitrary ticket worklog entries via unspecified vectors. IBM X-Force ID: 106460.
0
Attacker Value
Unknown
CVE-2015-9257
Disclosure Date: March 24, 2018 (last updated November 26, 2024)
BMC Remedy Action Request (AR) System 9.0 before 9.0.00 Service Pack 2 hot fix 1 has persistent XSS.
0
Attacker Value
Unknown
CVE-2017-18228
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
0
Attacker Value
Unknown
CVE-2017-18223
Disclosure Date: March 10, 2018 (last updated November 26, 2024)
BMC Remedy AR System before 9.1 SP3, when Remedy AR Authentication is enabled, allows attackers to obtain administrative access.
0
Attacker Value
Unknown
CVE-2017-5943
Disclosure Date: July 03, 2017 (last updated November 26, 2024)
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information about cross-site request forgery (CSRF) verification tokens via a crafted URL.
0
Attacker Value
Unknown
CVE-2016-6127
Disclosure Date: July 03, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.
0