|
252691
|
6.6 |
MEDIUM
Network
|
ovirt redhat
|
ovirt virtualization
|
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15113
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252692
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15125
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252693
|
7.5 |
HIGH
Network
|
powerdns debian
|
recursor debian_linux
|
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15120
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252694
|
5.3 |
MEDIUM
Network
|
redhat
|
openshift openshift_container_platform
|
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from …
|
-
|
CVE-2017-15137
|
2024-11-21 12:14 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252695
|
5.9 |
MEDIUM
Network
|
broadcom
|
ssl_visibility_appliance
|
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV ver…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-15533
|
2024-11-21 12:14 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252696
|
5.4 |
MEDIUM
Network
|
phpipam
|
phpipam
|
app/sections/user-menu.php in phpIPAM before 1.3.1 has XSS via the ip parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-15640
|
2024-11-21 12:14 |
2018-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252697
|
4.3 |
MEDIUM
Network
|
huawei
|
s12700_firmware s7700_firmware s9700_firmware
|
S12700 V200R005C00, V200R006C00, V200R006C01, V200R007C00, V200R007C01, V200R007C20, V200R008C00, V200R008C06, V200R009C00, V200R010C00, S7700 V200R001C00, V200R001C01, V200R002C00, V200R003C00, V200…
|
CWE-200
Information Exposure
|
CVE-2017-15327
|
2024-11-21 12:14 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252698
|
6.7 |
MEDIUM
Local
|
symantec
|
norton_app_lock
|
The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of circumstance, the exploit can allow the user to kill the app to prevent it from l…
|
CWE-287
Improper Authentication
|
CVE-2017-15534
|
2024-11-21 12:14 |
2018-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252699
|
4.3 |
MEDIUM
Network
|
huawei
|
dbs3900_tdd_lte_firmware
|
DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE supports SSL/TLS protocol negotiation using insecure encryption algorithms. If an ins…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2017-15326
|
2024-11-21 12:14 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252700
|
7.8 |
HIGH
Local
|
huawei
|
prague-al00a_firmware prague-al00b_firmware prague-al00c_firmware prague-tl00a_firmware prague-tl10a_firmware
|
The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Prague-AL00BC00B211, versions earlier than Prague-AL00CC00B211, versions earlier …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-15325
|
2024-11-21 12:14 |
2018-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|