VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5752 CVEsRSS

CVE-2019-11358Medium· 6.1⚠ ExploitedPoC
7y ago

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

XSS in jQuery as used in Drupal, Backdrop CMS, and other products

▾ Twilightjquery · jqueryEPSS 87%via OSV
CVE-2019-10255Medium· 6.1
7y ago

Open Redirect vulnerability in jupyterhub and notebook

Open Redirect vulnerability in jupyterhub and notebook

▾ Sunlitnotebook · notebookEPSS 1.8%via OSV
CVE-2018-20998Critical· 9.8
7y ago

Enum repr causing potential memory corruption

Enum repr causing potential memory corruption

▾ Midnightarrayfire · arrayfireEPSS 1.7%via OSV
CVE-2018-20996Critical· 9.8
7y ago

MsQueue and SegQueue suffer from double-free

MsQueue and SegQueue suffer from double-free

▾ Midnightcrossbeam · crossbeamEPSS 1.7%via OSV
CVE-2018-13796Medium· 6.5
8y ago

Moderate severity vulnerability that affects mailman

Moderate severity vulnerability that affects mailman

▾ Sunlitmailman · mailmanEPSS 2.5%via OSV
CVE-2011-1948Medium· 6.1
8y ago

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool

▾ Sunlitproducts-passwordresettool · products-passwordresettoolEPSS 2.4%via OSV
CVE-2011-1950Medium· 6.5⚠ Exploited
8y ago

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts

▾ Twilightplone-app-users · plone-app-usersEPSS 2.3%via OSV
CVE-2010-1104Medium
8y ago

Moderate severity vulnerability that affects Zope2

Moderate severity vulnerability that affects Zope2

▾ Sunlitzope2 · zope2EPSS 2.0%via OSV
CVE-2009-0662Medium
8y ago

Moderate severity vulnerability that affects Products.PlonePAS

Moderate severity vulnerability that affects Products.PlonePAS

▾ Sunlitproducts-plonepas · products-plonepasEPSS 0.97%via OSV
CVE-2011-2528High
8y ago

High severity vulnerability that affects Plone and Zope2

High severity vulnerability that affects Plone and Zope2

▾ Twilightplone · ploneEPSS 2.0%via OSV
CVE-2018-20991Critical· 9.8
8y ago

Possible double free during unwinding in SmallVec::insert_many

Possible double free during unwinding in SmallVec::insert_many

▾ Midnightsmallvec · smallvecEPSS 1.8%via OSV
CVE-2017-2673High· 7.2
8y ago

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated fe…

An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles…

▾ Twilightkeystone · keystoneEPSS 2.1%via OSV
CVE-2018-1000164High· 7.5
8y ago

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

Gunicorn contains Improper Neutralization of CRLF sequences in HTTP headers

▾ Twilightgunicorn · gunicornEPSS 2.4%via OSV
CVE-2018-1000516Medium· 6.1
8y ago

The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in …

The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow f…

▾ Sunlitgalaxy-app · galaxy-appEPSS 1.1%via OSV
CVE-2016-6903Critical· 9.9
9y ago

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

▾ Midnightlimited-shell · limited-shellEPSS 5.0%via OSV
CVE-2016-6902Critical· 9.9
9y ago

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

▾ Midnightlimited-shell · limited-shellEPSS 5.1%via OSV
CVE-2017-7200Medium· 5.8
9y ago

An SSRF issue was discovered in OpenStack Glance before Newton

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'ht…

▾ Sunlitopenstack · glanceEPSS 2.1%via NVD
CVE-2015-1881None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

▾ Sunlitglance · glanceEPSS 2.1%via OSV
CVE-2014-9684None
11y ago

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authe…

OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images …

▾ Sunlitglance · glanceEPSS 2.0%via OSV
CVE-2014-0006None
12y ago

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers …

The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

▾ Sunlitswift · swiftEPSS 1.9%via OSV
CVE-2013-1865None
13y ago

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which …

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

▾ Sunlitkeystone · keystoneEPSS 2.6%via OSV
CVE-2010-3198None
16y ago

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker thre…

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

▾ Sunlitzope · zopeEPSS 1.5%via OSV
CVEs tagged “osv” — page 192 · VulnSea