|
251711
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux
|
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15116
|
2024-11-21 12:14 |
2017-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251712
|
7.2 |
HIGH
Network
|
cs-cart
|
cs-cart
|
The files function in the administration section in CS-Cart 4.6.2 and earlier allows attackers to execute arbitrary PHP code via vectors involving a custom page.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15673
|
2024-11-21 12:14 |
2017-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251713
|
7.5 |
HIGH
Network
|
samba redhat debian canonical
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux ubuntu_linux
|
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15275
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251714
|
8.1 |
HIGH
Network
|
teampass
|
teampass
|
TeamPass before 2.1.27.9 does not properly enforce item access control when requesting items.queries.php. It is then possible to copy any arbitrary item into a directory controlled by the attacker, e…
|
CWE-269
Improper Privilege Management
|
CVE-2017-15055
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251715
|
7.5 |
HIGH
Network
|
teampass
|
teampass
|
An arbitrary file upload vulnerability, present in TeamPass before 2.1.27.9, allows remote authenticated users to upload arbitrary files leading to Remote Command Execution. To exploit this vulnerabi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-15054
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251716
|
4.9 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting roles.queries.php. It is then possible for a manager user to modify any arbitrary roles within the applicatio…
|
CWE-269
Improper Privilege Management
|
CVE-2017-15053
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251717
|
4.9 |
MEDIUM
Network
|
teampass
|
teampass
|
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or m…
|
CWE-269
Improper Privilege Management
|
CVE-2017-15052
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251718
|
5.4 |
MEDIUM
Network
|
teampass
|
teampass
|
Multiple stored cross-site scripting (XSS) vulnerabilities in TeamPass before 2.1.27.9 allow authenticated remote attackers to inject arbitrary web script or HTML via the (1) URL value of an item or …
|
CWE-79
Cross-site Scripting
|
CVE-2017-15051
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251719
|
8.1 |
HIGH
Network
|
redhat
|
openstack_platform
|
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authenticati…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-15114
|
2024-11-21 12:14 |
2017-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251720
|
6.1 |
MEDIUM
Network
|
theforeman redhat
|
foreman satellite satellite_capsule
|
An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts page, when clicking on the "chart" button and hovering over the chart; (2) Trends…
|
-
|
CVE-2017-15100
|
2024-11-21 12:14 |
2017-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|