1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2008-1281
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2008 1 PoC

Directory traversal vulnerability in TFTPsrvs.exe 2.5.3.1 and earlier, as used in Argon Technology Client Management Services (CMS) 1.31 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

CVE-2008-1968
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.5%
2008 1 PoC

Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.

CVE-2017-0913
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

CVE-2017-3823
Cisco WebEx browser extensions DevOps Networking
N/A
UNKNOWN
EPSS
80.4%
2017 CWE-119 1 PoC

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on Internet Explorer. A vulnerability in these Cisco WebEx browser extensions could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Me

CVE-2017-10385
GlassFish Server DevOps Web Database
N/A
UNKNOWN
EPSS
0.4%
2017 1 PoC

Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Web Container). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data as well as unauthorized read access to a subset of Oracle Gl

CVE-2017-17716
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

CVE-2017-2935
Adobe Flash Player 24.0.0.186 and earlier. DevOps
N/A
UNKNOWN
EPSS
69.1%
2017 1 PoC

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

CVE-2017-18509
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2017 4 PoCs

An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code under certain circumstances. The issue can be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN capability) or after namespace unsharing. This occurs because sk_type and protocol are not checked in the appropriate part of the ip6_mroute_* functions. NOTE: this affects Linux distributions that use 4.9.x lon

CVE-2017-0915
GitLab Community and Enterprise Editions DevOps
N/A
UNKNOWN
EPSS
1.2%
2017 CWE-77 1 PoC

Gitlab Community Edition version 10.2.4 is vulnerable to a lack of input validation in the GitlabProjectsImportService resulting in remote code execution.

CVE-2017-15223
Software Genérico DevOps
N/A
UNKNOWN
EPSS
17.2%
2017 1 PoC

Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.

CVE-2017-14179
Apport DevOps
N/A
UNKNOWN
EPSS
0.0%
2017 2 PoCs

Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.

CVE-2017-12426
Software Genérico DevOps Networking
N/A
UNKNOWN
EPSS
0.6%
2017 1 PoC

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

CVE-2017-11107
Software Genérico DevOps Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVE-2019-6792
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2019 1 PoC

An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It allows Path Disclosure. When an error is encountered on project import, the error message will display instance internal information.

CVE-2017-8928
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.

CVE-2014-3665
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.

CVE-2013-5676
Software Genérico DevOps
N/A
UNKNOWN
EPSS
5.3%
2013 1 PoC

The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

CVE-2017-14992
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2017 1 PoC

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.

CVE-2019-5463
GitLab CE/EE DevOps
N/A
UNKNOWN
EPSS
0.2%
2019 CWE-200 1 PoC

An authorization issue was discovered in the GitLab CE/EE CI badge images endpoint which could result in disclosure of the build status. This vulnerability was addressed in 12.1.2, 12.0.4, and 11.11.6.

CVE-2017-10123
WebLogic Server DevOps Web Database
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container). The supported version that is affected is 12.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).