|
255121
|
7.4 |
HIGH
Network
|
samba redhat debian hp
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux debian_linux enterprise_linux_server_aus enterprise_linux_server_eus cifs_server
|
A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and…
|
CWE-310
Cryptographic Issues
|
CVE-2017-12151
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255122
|
7.4 |
HIGH
Network
|
samba redhat debian
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server gluster_storage debian_linux
|
It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-…
|
NVD-CWE-noinfo
|
CVE-2017-12150
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255123
|
5.4 |
MEDIUM
Network
|
redhat
|
satellite
|
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
|
-
|
CVE-2017-12175
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255124
|
6.5 |
MEDIUM
Network
|
redhat apache
|
enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux http_server
|
A regression was found in the Red Hat Enterprise Linux 6.9 version of httpd 2.2.15-60, causing comments in the "Allow" and "Deny" configuration lines to be parsed incorrectly. A web administrator cou…
|
-
|
CVE-2017-12171
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255125
|
5.5 |
MEDIUM
Local
|
redhat
|
jboss_enterprise_application_platform
|
It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users …
|
CWE-200
Information Exposure
|
CVE-2017-12167
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255126
|
6.4 |
MEDIUM
Physics
|
gnome
|
gnome_display_manager
|
A flaw was discovered in gdm 3.24.1 where gdm greeter was no longer setting the ran_once boolean during autologin. If autologin was enabled for a victim, an attacker could simply select 'login as ano…
|
CWE-665
Improper Initialization
|
CVE-2017-12164
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255127
|
7.1 |
HIGH
Adjacent
|
samba redhat debian
|
samba enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server gluster_storage debian_linux
|
An information leak flaw was found in the way SMB1 protocol was implemented by Samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8. A malicious client could use this flaw to dump server …
|
-
|
CVE-2017-12163
|
2024-11-21 12:08 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255128
|
8.8 |
HIGH
Network
|
opcfoundation
|
ua-.net-legacy
|
Unsigned versions of the DLLs distributed by the OPC Foundation may be replaced with malicious code.
|
CWE-20
Improper Input Validation
|
CVE-2017-12070
|
2024-11-21 12:08 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255129
|
7.8 |
HIGH
Local
|
opcfoundation
|
local_discovery_server
|
The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double quotes around the opcualds.exe executable path, which might allow local users t…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2017-11672
|
2024-11-21 12:08 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255130
|
7.2 |
HIGH
Network
|
synology
|
router_manager
|
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter.
|
CWE-77
Command Injection
|
CVE-2017-12078
|
2024-11-21 12:08 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|