Latest CVE Feed
-
9.8
CRITICALCVE-2017-7481
Ansible before versions 2.3.1.0 and 2.4.0.0 fails to properly mark lookup-plugin results as unsafe. If an attacker could control the results of lookup() calls, they could inject Unicode strings to be parsed by the jinja2 templating system, resulting in co... Read more
- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
9.0
CRITICALCVE-2017-7471
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest c... Read more
Affected Products : qemu- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7470
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.... Read more
- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-7468
In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, a... Read more
- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7467
A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could potentially use this flaw to crash minicom, or execute arbitrary code in the context of the minicom process.... Read more
Affected Products : minicom- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
8.5
HIGHCVE-2017-7466
Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use ... Read more
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7465
It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in ... Read more
Affected Products : jboss_enterprise_application_platform- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7464
It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.... Read more
Affected Products : jboss_enterprise_application_platform- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7463
JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful... Read more
Affected Products : jboss_bpm_suite- Published: Jul. 27, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7438
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via javascript DOM modification using the supplied cookie parameter.... Read more
Affected Products : privileged_account_manager- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7437
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.... Read more
Affected Products : privileged_account_manager- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-7436
In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.... Read more
Affected Products : libzypp- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-7435
In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malicious servers to inject malicious RPM packages into a users system.... Read more
Affected Products : libzypp- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-7434
In the JDBC driver of NetIQ Identity Manager before 4.6 sending out incorrect XML configurations could result in passwords being logged into exception logfiles.... Read more
Affected Products : identity_manager- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-7429
The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code which could be used by authenticated attackers to execute JSP applets on the iManager server.... Read more
- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7427
Multiple cross site scripting attacks were found in the Identity Manager Plug-in, hosted on iManager 2.7.7.7, before Identity Manager 4.6.1. In certain scenarios it was possible to execute arbitrary JavaScript code in the context of vulnerable application... Read more
Affected Products : identity_manager- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2017-7426
The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to leak information or cause denial of service attacks.... Read more
Affected Products : identity_manager- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-7419
A OAuth application in NetIQ Access Manager 4.3 before 4.3.2 and 4.2 before 4.2.4 allowed cross site scripting attacks due to unescaped "description" field that could be specified by the provider.... Read more
Affected Products : access_manager- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-7399
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.... Read more
Affected Products : cloudera_manager- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-7376
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.... Read more
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024