|
249521
|
7.5 |
HIGH
Network
|
openstack redhat
|
nova openstack
|
An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt t…
|
NVD-CWE-noinfo
|
CVE-2017-18191
|
2024-11-21 12:19 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249522
|
5.3 |
MEDIUM
Network
|
atlassian
|
crucible
|
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to …
|
CWE-863
Incorrect Authorization
|
CVE-2017-18095
|
2024-11-21 12:19 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249523
|
4.8 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allow remote attackers who have permission to add or modify a repository to inj…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18093
|
2024-11-21 12:19 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249524
|
5.4 |
MEDIUM
Network
|
atlassian
|
crucible
|
The print snippet resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site sc…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18092
|
2024-11-21 12:19 |
2018-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249525
|
4.8 |
MEDIUM
Network
|
atlassian
|
fisheye crucible
|
The admin backupprogress action in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and before 4.5.0 allows remote attackers with administrative privileges to inject …
|
CWE-79
Cross-site Scripting
|
CVE-2017-18091
|
2024-11-21 12:19 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249526
|
6.1 |
MEDIUM
Network
|
atlassian
|
fisheye
|
Various resources in Atlassian Fisheye before version 4.5.1 (the fixed version for 4.5.x) and before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18090
|
2024-11-21 12:19 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249527
|
5.4 |
MEDIUM
Network
|
atlassian
|
crucible
|
The view review history resource in Atlassian Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scr…
|
CWE-79
Cross-site Scripting
|
CVE-2017-18089
|
2024-11-21 12:19 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249528
|
7.5 |
HIGH
Network
|
apple debian canonical
|
cups debian_linux ubuntu_linux
|
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemo…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2017-18190
|
2024-11-21 12:19 |
2018-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249529
|
7.5 |
HIGH
Network
|
sound_exchange_project debian
|
sound_exchange debian_linux
|
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allo…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-18189
|
2024-11-21 12:19 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249530
|
4.3 |
MEDIUM
Network
|
atlassian
|
bitbucket
|
Various plugin servlet resources in Atlassian Bitbucket Server before version 5.3.7 (the fixed version for 5.3.x), from version 5.4.0 before 5.4.6 (the fixed version for 5.4.x), from version 5.5.0 be…
|
CWE-20
Improper Input Validation
|
CVE-2017-18088
|
2024-11-21 12:19 |
2018-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|