1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2018-2475
project “Gardener” DevOps Web
N/A
UNKNOWN
EPSS
0.7%
2018 1 PoC

Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot's apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes security issues, the missing network isolation theoretically can lead to compromise other shoot or seed clusters in the "Gardener" context. The issue is rated high due to the high impact of a potential exploitation in "Gardener" context. This was fixed in Gardener release 0.12.4.

CVE-2015-2925
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.7%
2015 3 PoCs

The prepend_path function in fs/dcache.c in the Linux kernel before 4.2.4 does not properly handle rename actions inside a bind mount, which allows local users to bypass an intended container protection mechanism by renaming a directory, related to a "double-chroot attack."

CVE-2018-19039
Software Genérico DevOps
N/A
UNKNOWN
EPSS
9.2%
2018 1 PoC

Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.

CVE-2021-28146
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.3%
2021 2 PoCs

The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to grant a user team permissions that the user isn't supposed to have.

CVE-2018-1999005
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.2%
2018 1 PoC

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

CVE-2010-4214
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.3%
2010 1 PoC

The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.

CVE-2010-3514
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
12.7%
2010 1 PoC

Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 6.1 and 7.0 allows remote attackers to affect integrity via unknown vectors related to Web Container.

CVE-2010-1262
Software Genérico DevOps
N/A
UNKNOWN
EPSS
63.4%
2010 1 PoC

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of the root container, aka "Memory Corruption Vulnerability."

CVE-2021-33924
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.8%
2021 2 PoCs

Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its auxiliary component that allows remote attackers to access sensitive information.

CVE-2010-0067
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.7%
2010 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect confidentiality via unknown vectors.

CVE-2010-3209
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.9%
2010 1 PoC

Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code via a URL in the includeFile parameter to (1) Config/Container.php and (2) HTML/QuickForm.php in fog/lib/pear/, the (3) driverpath parameter to fog/lib/pear/DB/NestedSet.php, and the (4) path parameter to fog/lib/pear/DB/NestedSet/Output.php.

CVE-2010-0070
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.6%
2010 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect integrity via unknown vectors.

CVE-2010-0891
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.9%
2010 1 PoC

Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.

CVE-2010-4437
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
48.9%
2010 1 PoC

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Servlet Container.

CVE-2010-4453
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.5%
2010 1 PoC

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 7.0.7, 8.1.6, 9.0, 9.1, 9.2.4, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect integrity via unknown vectors related to Servlet Container.

CVE-2010-1398
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
10.4%
2010 1 PoC

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an unspecified element into an editable container and the access of an uninitialized element.

CVE-2010-0164
Software Genérico DevOps
N/A
UNKNOWN
EPSS
7.5%
2010 1 PoC

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.

CVE-2021-4178
kubernetes-client DevOps
N/A
UNKNOWN
EPSS
0.1%
2021 CWE-502 1 PoC

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

CVE-2010-1396
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
10.6%
2010 1 PoC

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the contentEditable attribute and removing container elements.