|
249131
|
8.1 |
HIGH
Network
|
jenkins
|
active_directory
|
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2649
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249132
|
5.6 |
MEDIUM
Network
|
jenkins
|
ssh_slaves
|
It was found that jenkins-ssh-slaves-plugin before version 1.15 did not perform host key verification, thereby enabling Man-in-the-Middle attacks.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2648
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249133
|
7.5 |
HIGH
Network
|
linux redhat
|
linux_kernel enterprise_linux_server enterprise_linux_workstation enterprise_linux_desktop enterprise_linux_server_aus
|
It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP conne…
|
-
|
CVE-2017-2634
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249134
|
6.5 |
MEDIUM
Network
|
qemu redhat
|
qemu enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-2633
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249135
|
4.9 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine cloudforms
|
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have.…
|
CWE-863
Incorrect Authorization
|
CVE-2017-2632
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249136
|
6.5 |
MEDIUM
Network
|
haxx
|
curl
|
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or f…
|
CWE-295
Improper Certificate Validation
|
CVE-2017-2629
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249137
|
5.5 |
MEDIUM
Local
|
freedesktop redhat
|
libice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the proc…
|
-
|
CVE-2017-2626
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249138
|
9.9 |
CRITICAL
Network
|
qemu redhat citrix debian xen
|
qemu enterprise_linux_desktop xenserver enterprise_linux_workstation openstack enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus …
|
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cpu…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-2620
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249139
|
5.5 |
MEDIUM
Local
|
linux redhat debian
|
linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus
|
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to …
|
-
|
CVE-2017-2618
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249140
|
4.7 |
MEDIUM
Local
|
util-linux_project redhat debian
|
util-linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus
|
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root pr…
|
CWE-362
Race Condition
|
CVE-2017-2616
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|