Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Proget MEDIUM 6.5
CVE-2017-15608

Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.

Fix: 5.0.4+
Fix from $1,600 2018-09-26
Otter CRITICAL 9.8
CVE-2017-15607

Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.

Fix: 1.7.4+
Fix from $2,300 2017-12-01
Otter CRITICAL 9.8
CVE-2017-17086

Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (cr…

Fix: after 1.7.4
Fix from $2,300 2017-12-01
Buildmaster HIGH 7.5
CVE-2017-16520

Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.

Fix: 5.8.2+
Fix from $1,950 2017-11-11
Buildmaster CRITICAL 9.8
CVE-2017-16521

In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.

Fix: 5.8.2+
Fix from $2,300 2017-11-10
Buildmaster MEDIUM 6.1
CVE-2017-16760

Inedo BuildMaster before 5.8.2 has XSS.

Fix: 5.8.2+
Fix from $1,600 2017-11-10
Buildmaster MEDIUM 6.1
CVE-2017-16761

An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.

Fix: 5.8.2+
Fix from $1,600 2017-11-10
Proget HIGH 7.5
CVE-2017-14944

Inedo ProGet before 4.7.14 does not properly address dangerous package IDs during package addition, aka PG-1060.

Fix: after 4.7.13
Fix from $1,950 2017-09-30