|
253001
|
7.5 |
HIGH
Network
|
openstack redhat
|
cinder openstack
|
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically af…
|
CWE-200
Information Exposure
|
CVE-2017-15139
|
2024-11-21 12:14 |
2018-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253002
|
5.0 |
MEDIUM
Network
|
redhat
|
openshift_container_platform
|
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
|
CWE-200
Information Exposure
|
CVE-2017-15138
|
2024-11-21 12:14 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253003
|
7.0 |
HIGH
Local
|
charlesproxy
|
charles
|
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.
|
CWE-362
Race Condition
|
CVE-2017-15358
|
2024-11-21 12:14 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253004
|
9.8 |
CRITICAL
Network
|
qemu redhat canonical
|
qemu enterprise_linux ubuntu_linux
|
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be li…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-15118
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253005
|
9.8 |
CRITICAL
Network
|
liblouis redhat
|
liblouis enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15101
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253006
|
6.7 |
MEDIUM
Local
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the serv…
|
-
|
CVE-2017-15097
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253007
|
8.6 |
HIGH
Network
|
qemu canonical debian redhat
|
qemu ubuntu_linux debian_linux virtualization
|
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste C…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15119
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253008
|
6.6 |
MEDIUM
Network
|
ovirt redhat
|
ovirt virtualization
|
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-15113
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253009
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15125
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253010
|
7.5 |
HIGH
Network
|
powerdns debian
|
recursor debian_linux
|
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15120
|
2024-11-21 12:14 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|