|
248811
|
7.8 |
HIGH
Local
|
redhat
|
subscription-manager
|
It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.Facts.GetFacts and com.redhat.RHSM1.Config.Set methods. An unprivileged local a…
|
NVD-CWE-noinfo
|
CVE-2017-2663
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248812
|
8.8 |
HIGH
Network
|
jenkins
|
distributed_fork
|
It was found that there were no permission checks performed in the Distributed Fork plugin before and including 1.5.0 for Jenkins that provides the dist-fork CLI command beyond the basic check for Ov…
|
CWE-287
Improper Authentication
|
CVE-2017-2652
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248813
|
8.5 |
HIGH
Network
|
jenkins
|
pipeline_classpath_step
|
It was found that the use of Pipeline: Classpath Step Jenkins plugin enables a bypass of the Script Security sandbox for users with SCM commit access, as well as users with e.g. Job/Configure permiss…
|
NVD-CWE-noinfo
|
CVE-2017-2650
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248814
|
8.1 |
HIGH
Network
|
jenkins
|
active_directory
|
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2649
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248815
|
5.6 |
MEDIUM
Network
|
jenkins
|
ssh_slaves
|
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2648
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248816
|
7.5 |
HIGH
Network
|
linux redhat
|
linux_kernel enterprise_linux_server enterprise_linux_workstation enterprise_linux_desktop enterprise_linux_server_aus
|
It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP conne…
|
-
|
CVE-2017-2634
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248817
|
6.5 |
MEDIUM
Network
|
qemu redhat
|
qemu enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-2633
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248818
|
4.9 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine cloudforms
|
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have.…
|
CWE-863
Incorrect Authorization
|
CVE-2017-2632
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248819
|
6.5 |
MEDIUM
Network
|
haxx
|
curl
|
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or f…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2629
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248820
|
5.5 |
MEDIUM
Local
|
freedesktop redhat
|
libice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the proc…
|
-
|
CVE-2017-2626
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|