Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2019-11358Medium· 6.1⚠ ExploitedPoCXSS in jQuery as used in Drupal, Backdrop CMS, and other products
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2019-10255Medium· 6.1Open Redirect vulnerability in jupyterhub and notebook
Open Redirect vulnerability in jupyterhub and notebook
CVE-2018-20998Critical· 9.8Enum repr causing potential memory corruption
Enum repr causing potential memory corruption
CVE-2018-20996Critical· 9.8MsQueue and SegQueue suffer from double-free
MsQueue and SegQueue suffer from double-free
CVE-2018-13796Medium· 6.5Moderate severity vulnerability that affects mailman
Moderate severity vulnerability that affects mailman
CVE-2011-1948Medium· 6.1Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
CVE-2011-1950Medium· 6.5⚠ ExploitedPlone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
CVE-2010-1104MediumModerate severity vulnerability that affects Zope2
Moderate severity vulnerability that affects Zope2
CVE-2009-0662MediumModerate severity vulnerability that affects Products.PlonePAS
Moderate severity vulnerability that affects Products.PlonePAS
CVE-2011-2528HighHigh severity vulnerability that affects Plone and Zope2
High severity vulnerability that affects Plone and Zope2
CVE-2018-20991Critical· 9.8Possible double free during unwinding in SmallVec::insert_many
Possible double free during unwinding in SmallVec::insert_many
CVE-2017-2673High· 7.2An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…
CVE-2018-1000164High· 7.5Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers
CVE-2018-1000516Medium· 6.1The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in …
The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow f…
CVE-2016-6903Critical· 9.9lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
CVE-2016-6902Critical· 9.9lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
CVE-2017-7200Medium· 5.8An SSRF issue was discovered in OpenStack Glance before Newton
An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…
CVE-2015-1881NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-9684NoneOpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…
OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …
CVE-2014-0006NoneThe TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …
The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.
CVE-2013-1865NoneOpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …
OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.
CVE-2010-3198NoneZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker thre…
ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.