|
248571
|
7.5 |
HIGH
Network
|
qemu redhat
|
qemu openstack virtualization
|
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-…
|
-
|
CVE-2017-7539
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248572
|
5.9 |
MEDIUM
Network
|
openstack redhat
|
neutron openstack
|
A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutro…
|
-
|
CVE-2017-7543
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248573
|
7.5 |
HIGH
Network
|
redhat dogtagpki
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server dogtagpki
|
It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4. An attacker could potentially use this flaw to by…
|
-
|
CVE-2017-7537
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248574
|
6.1 |
MEDIUM
Network
|
theforeman
|
foreman
|
foreman before version 1.16.0 is vulnerable to a stored XSS in organizations/locations assignment to hosts. Exploiting this requires a user to actively assign hosts to an organization that contains h…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7535
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248575
|
8.8 |
HIGH
Network
|
redhat
|
cloudforms cloudforms_management_engine
|
In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will e…
|
NVD-CWE-noinfo
|
CVE-2017-7530
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248576
|
6.8 |
MEDIUM
Network
|
gnupg canonical debian
|
libgcrypt ubuntu_linux debian_linux
|
libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right method for computing the sliding-window expansion…
|
CWE-310
Cryptographic Issues
|
CVE-2017-7526
|
2024-11-21 12:32 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248577
|
9.8 |
CRITICAL
Network
|
eclipse debian oracle hp netapp
|
jetty debian_linux retail_xstore_point_of_service retail_xstore_payment rest_data_services xp_p9000_command_view snap_creator_framework santricity_cloud_connector snapcenter
|
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the…
|
CWE-444
HTTP Request Smuggling
|
CVE-2017-7658
|
2024-11-21 12:32 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248578
|
9.8 |
CRITICAL
Network
|
eclipse debian netapp hp oracle
|
jetty debian_linux oncommand_unified_manager element_software santricity_cloud_connector element_software_management_node e-series_santricity_web_services e-series_santricity_man…
|
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk l…
|
CWE-190 CWE-444
Integer Overflow or Wraparound HTTP Request Smuggling
|
CVE-2017-7657
|
2024-11-21 12:32 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248579
|
7.5 |
HIGH
Network
|
eclipse debian
|
jetty debian_linux
|
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line…
|
NVD-CWE-noinfo
|
CVE-2017-7656
|
2024-11-21 12:32 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248580
|
5.3 |
MEDIUM
Network
|
netapp
|
oncommand_unified_manager
|
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is…
|
CWE-200
Information Exposure
|
CVE-2017-7568
|
2024-11-21 12:32 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|