|
251471
|
5.3 |
MEDIUM
Network
|
powerdns
|
recursor
|
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized us…
|
CWE-20
Improper Input Validation
|
CVE-2017-15093
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251472
|
7.1 |
HIGH
Network
|
powerdns
|
authoritative
|
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the …
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2017-15091
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251473
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed dat…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-15090
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251474
|
7.8 |
HIGH
Local
|
keycloak-httpd-client-install_project
|
keycloak-httpd-client-install
|
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
|
CWE-200
Information Exposure
|
CVE-2017-15112
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251475
|
5.5 |
MEDIUM
Local
|
keycloak-httpd-client-install_project
|
keycloak-httpd-client-install
|
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
|
CWE-59
Link Following
|
CVE-2017-15111
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251476
|
7.8 |
HIGH
Local
|
spice-space debian
|
spice-vdagent debian_linux
|
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary comm…
|
-
|
CVE-2017-15108
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251477
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15128
|
2024-11-21 12:14 |
2018-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251478
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local den…
|
-
|
CVE-2017-15127
|
2024-11-21 12:14 |
2018-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251479
|
8.1 |
HIGH
Network
|
linux
|
linux_kernel
|
A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly…
|
-
|
CVE-2017-15126
|
2024-11-21 12:14 |
2018-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251480
|
7.2 |
HIGH
Network
|
tp-link
|
er5110g_firmware er5120g_firmware er5510g_firmware er5520g_firmware r4149g_firmware r4239g_firmware r4299g_firmware r473gp-ac_firmware r473g_firmware r473p-ac_firmware r…
|
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.
|
NVD-CWE-noinfo
|
CVE-2017-15637
|
2024-11-21 12:14 |
2018-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|