|
251391
|
9.8 |
CRITICAL
Network
|
qemu redhat canonical
|
qemu enterprise_linux ubuntu_linux
|
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be li…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15118
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251392
|
9.8 |
CRITICAL
Network
|
liblouis redhat
|
liblouis enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15101
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251393
|
6.7 |
MEDIUM
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the serv…
|
-
|
CVE-2017-15097
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251394
|
8.6 |
HIGH
Network
|
qemu canonical debian redhat
|
qemu ubuntu_linux debian_linux virtualization
|
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste C…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15119
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251395
|
6.6 |
MEDIUM
Network
|
ovirt redhat
|
ovirt virtualization
|
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15113
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251396
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15125
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251397
|
7.5 |
HIGH
Network
|
powerdns debian
|
recursor debian_linux
|
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15120
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251398
|
5.3 |
MEDIUM
Network
|
redhat
|
openshift openshift_container_platform
|
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from …
|
-
|
CVE-2017-15137
|
2024-11-21 12:14 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251399
|
5.9 |
MEDIUM
Network
|
broadcom
|
ssl_visibility_appliance
|
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV ver…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-15533
|
2024-11-21 12:14 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251400
|
5.4 |
MEDIUM
Network
|
phpipam
|
phpipam
|
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15640
|
2024-11-21 12:14 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|