|
253081
|
5.3 |
MEDIUM
Network
|
nlnetlabs debian canonical
|
unbound debian_linux ubuntu_linux
|
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) o…
|
CWE-20
Improper Input Validation
|
CVE-2017-15105
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253082
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15094
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253083
|
6.1 |
MEDIUM
Network
|
powerdns
|
recursor
|
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15092
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253084
|
5.3 |
MEDIUM
Network
|
powerdns
|
recursor
|
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized us…
|
CWE-20
Improper Input Validation
|
CVE-2017-15093
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253085
|
7.1 |
HIGH
Network
|
powerdns
|
authoritative
|
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the …
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2017-15091
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253086
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed dat…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-15090
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253087
|
7.8 |
HIGH
Local
|
keycloak-httpd-client-install_project
|
keycloak-httpd-client-install
|
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
|
CWE-200
Information Exposure
|
CVE-2017-15112
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253088
|
5.5 |
MEDIUM
Local
|
keycloak-httpd-client-install_project
|
keycloak-httpd-client-install
|
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
|
CWE-59
Link Following
|
CVE-2017-15111
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253089
|
7.8 |
HIGH
Local
|
spice-space debian
|
spice-vdagent debian_linux
|
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary comm…
|
-
|
CVE-2017-15108
|
2024-11-21 12:14 |
2018-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253090
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux enterprise_mrg
|
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15128
|
2024-11-21 12:14 |
2018-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|