Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-01-26 CVE-2017-14593 Command Injection vulnerability in Atlassian Sourcetree
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling.
network
low complexity
atlassian CWE-77
8.8
2018-01-26 CVE-2017-14592 Command Injection vulnerability in Atlassian Sourcetree
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling.
network
low complexity
atlassian CWE-77
8.8
2018-01-26 CVE-2017-1000403 Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Speaks! 0.1/0.1.1
Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effectively elevating privileges to Overall/Run Scripts.
network
low complexity
jenkins CWE-732
8.8
2018-01-26 CVE-2017-1000394 Improper Input Validation vulnerability in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092.
network
low complexity
jenkins CWE-20
7.5
2018-01-26 CVE-2017-1000393 OS Command Injection vulnerability in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could configure a launch method called 'Launch agent via execution of command on master'.
network
low complexity
jenkins CWE-78
8.8
2018-01-26 CVE-2017-1000391 Improper Input Validation vulnerability in Jenkins
Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk.
network
low complexity
jenkins CWE-20
7.3
2018-01-26 CVE-2017-1000387 Insufficiently Protected Credentials vulnerability in Jenkins Build-Publisher
Jenkins Build-Publisher plugin version 1.21 and earlier stores credentials to other Jenkins instances in the file hudson.plugins.build_publisher.BuildPublisher.xml in the Jenkins master home directory.
local
low complexity
jenkins CWE-522
7.8
2018-01-26 CVE-2017-3762 Use of Hard-coded Credentials vulnerability in Lenovo Fingerprint Manager PRO 8.01.86
Sensitive data stored by Lenovo Fingerprint Manager Pro, version 8.01.86 and earlier, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system in which it is installed.
local
low complexity
lenovo CWE-798
7.8
2018-01-25 CVE-2016-10710 Improper Input Validation vulnerability in Biscom Secure File Transfer 5.0.1000/5.0.1048
Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential numbers, which allows remote authenticated users to overwrite or read files via crafted requests.
network
low complexity
biscom CWE-20
8.1
2018-01-25 CVE-2018-6315 Integer Overflow or Wraparound vulnerability in multiple products
The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds read, which may allow attackers to cause a denial of service or unspecified other impact via a crafted SWF file.
network
low complexity
libming debian CWE-190
8.8