1018 vulnerabilidades · DevOps Orden: CVSS EPSS Año ID
CVE-2014-0426
Software Genérico DevOps Web Database
N/A
UNKNOWN
EPSS
0.4%
2014 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect integrity via vectors related to HTTP Request Handling, a different vulnerability than CVE-2014-0413.

CVE-2014-4239
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.6%
2014 3 PoCs

Unspecified vulnerability in Oracle Sun Solaris 8, 9, 10, and 11.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Common Agent Container (Cacao).

CVE-2013-0331
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.4%
2013 1 PoC

Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.

CVE-2015-1856
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.9%
2015 1 PoC

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.

CVE-2010-1397
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
12.0%
2010 1 PoC

Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to a layout change during selection rendering and the DOCUMENT_POSITION_DISCONNECTED attribute in a container of an unspecified type.

CVE-2005-0519
Software Genérico DevOps
N/A
UNKNOWN
EPSS
1.2%
2005 1 PoC

ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.

CVE-2005-0696
Software Genérico DevOps
N/A
UNKNOWN
EPSS
7.2%
2005 1 PoC

Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.

CVE-2011-3566
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.7%
2011 1 PoC

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.2.4, 10.0.2, 10.3.3, 10.3.4, and 10.3.5 allows remote attackers to affect availability via unknown vectors related to Web Container.

CVE-2011-3559
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
1.3%
2011 1 PoC

Unspecified vulnerability in Oracle Communications Server 2.0; GlassFish Enterprise Server 2.1.1, 3.0.1, and 3.1.1; and Sun Java System App Server 8.1 and 8.2 allows remote attackers to affect availability via unknown vectors related to Web Container.

CVE-2021-4154
kernel DevOps
N/A
UNKNOWN
EPSS
0.8%
2021 CWE-416 3 PoCs

A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.

CVE-2011-2730
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
46.3%
2011 1 PoC

VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression

CVE-2011-0883
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.2%
2011 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.2.3, 10.1.3.5, 10.1.4.0.1, and 10.1.4.3 allows remote authenticated users to affect integrity, related to Servlet Runtime in OC4J.

CVE-2011-4344
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
0.4%
2011 1 PoC

Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone container is used, allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.

CVE-2011-2314
Software Genérico DevOps Database
N/A
UNKNOWN
EPSS
0.4%
2011 1 PoC

Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors related to JavaServer Pages.

CVE-2021-28148
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
5.7%
2021 2 PoCs

One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 is accessible without any authentication. This allows any unauthenticated user to send an unlimited number of requests to the endpoint, leading to a denial of service (DoS) attack against a Grafana Enterprise instance.

CVE-2022-31214
Software Genérico DevOps
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an environment in which the Linux user namespace is still the initial user namespace, the NO_NEW_PRIVS prctl is not activated, and the entered mount namespace is under the attacker's control. In this way, the filesystem layout can be adjusted to gain root privileges through execution of available setuid-root binaries such as su or sudo.

CVE-2022-42150
Software Genérico DevOps Cloud
N/A
UNKNOWN
EPSS
0.3%
2022 2 PoCs

TinyLab linux-lab v1.1-rc1 and cloud-labv0.8-rc2, v1.1-rc1 are vulnerable to insecure permissions. The default configuration could cause Container Escape.

CVE-2022-20614
Jenkins Mailer Plugin DevOps
N/A
UNKNOWN
EPSS
0.1%
2022 1 PoC

A missing permission check in Jenkins Mailer Plugin 391.ve4a_38c1b_cf4b_ and earlier allows attackers with Overall/Read access to use the DNS used by the Jenkins instance to resolve an attacker-specified hostname.

CVE-2015-1368
Software Genérico DevOps Web
N/A
UNKNOWN
EPSS
14.0%
2015 3 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to api/v1/schedules/.

CVE-2021-20253
ansible-tower DevOps
N/A
UNKNOWN
EPSS
0.3%
2021 CWE-552 1 PoC

A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker to elevate the privilege from a low privileged user to the awx user from outside the isolated environment. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.