|
249171
|
9.1 |
CRITICAL
Network
|
qemu redhat citrix debian xen
|
qemu enterprise_linux_desktop xenserver enterprise_linux_workstation openstack enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus …
|
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A pr…
|
-
|
CVE-2017-2615
|
2024-11-21 12:23 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249172
|
6.5 |
MEDIUM
Network
|
fedoraproject redhat
|
389_directory_server enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2668
|
2024-11-21 12:23 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249173
|
8.8 |
HIGH
Network
|
theforeman redhat
|
foreman satellite
|
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned system…
|
CWE-269
Improper Privilege Management
|
CVE-2017-2672
|
2024-11-21 12:23 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249174
|
7.5 |
HIGH
Network
|
dovecot debian
|
dovecot debian_linux
|
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_exp…
|
CWE-20
Improper Input Validation
|
CVE-2017-2669
|
2024-11-21 12:23 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249175
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-2598
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249176
|
7.8 |
HIGH
Local
|
hawt.io
|
hawtio
|
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-2617
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249177
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of t…
|
CWE-200
Information Exposure
|
CVE-2017-2609
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249178
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2607
|
2024-11-21 12:23 |
2018-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249179
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
jenkins before versions 2.44, 2.32.2 is vulnerable to a user creation CSRF using GET by admins. While this user record was only retained until restart in most cases, administrators' web browsers coul…
|
CWE-352
Origin Validation Error
|
CVE-2017-2613
|
2024-11-21 12:23 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249180
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in search suggestions due to improperly escaping users with less-than and greater-than characters in their names…
|
CWE-79
Cross-site Scripting
|
CVE-2017-2610
|
2024-11-21 12:23 |
2018-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|