Skip to main content

CWE archive

CWE-862 CVEs

Programmatic archive

8,672 CVEs tagged with CWE-862434 Critical, 1,954 High, 5,992 Medium, 291 Low, 1 Unrated.

CVE-2019-10868

Published Apr 5, 2019

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order record…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10293

Published Apr 4, 2019

A missing permission check in Jenkins Kmap Plugin in KmapJenkinsBuilder.DescriptorImpl form validation methods allows attackers with Overall/Read permission to initiate a connecti…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10290

Published Apr 4, 2019

A missing permission check in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10279

Published Apr 4, 2019

A missing permission check in Jenkins jenkins-reviewbot Plugin in the ReviewboardDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003099

Published Apr 4, 2019

A missing permission check in Jenkins openid Plugin in the OpenIdSsoSecurityRealm.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003093

Published Apr 4, 2019

A missing permission check in Jenkins Nomad Plugin in the NomadCloud.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initia…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003091

Published Apr 4, 2019

A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003087

Published Apr 4, 2019

A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003083

Published Apr 4, 2019

A missing permission check in Jenkins Gearman Plugin in the GearmanPluginConfig#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003081

Published Apr 4, 2019

A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Over…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003079

Published Apr 4, 2019

A missing permission check in Jenkins VMware Lab Manager Slaves Plugin in the LabManager.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003077

Published Apr 4, 2019

A missing permission check in Jenkins Audit to Database Plugin in the DbAuditPublisherDescriptorImpl#doTestJdbcConnection form validation method allows attackers with Overall/Read…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003059

Published Apr 4, 2019

A missing permission check in Jenkins FTP publisher Plugin in the FTPPublisher.DescriptorImpl#doLoginCheck method allows attackers with Overall/Read permission to initiate a conne…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10648

Published Mar 30, 2019

Robocode through 1.9.3.5 allows remote attackers to cause external service interaction (DNS), as demonstrated by a query for a unique subdomain name within an attacker-controlled…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-1003047

Published Mar 28, 2019

A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-sp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1003043

Published Mar 28, 2019

A missing permission check in Jenkins Slack Notification Plugin 2.19 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3879

Published Mar 25, 2019

It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be perf…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3835

Published Mar 25, 2019

It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to,…

CVSS 5.5 · Medium

CVE-2018-4059

Published Mar 21, 2019

An exploitable unsafe default configuration vulnerability exists in the TURN server function of coTURN prior to version 4.5.0.9. By default, the TURN server runs an unauthenticate…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-17491

Published Mar 21, 2019

EasyLobby Solo could allow a local attacker to gain elevated privileges on the system. By visiting the kiosk and typing "esc" to exit the program, an attacker could exploit this v…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-17490

Published Mar 21, 2019

EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 8,501-8,525 of 8,672 CVEsPage 341 of 347