Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-12157

около 9 лет назад

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2017-12156

около 9 лет назад

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-12155

почти 9 лет назад

A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenStack as though the attacker were the OpenStack service, thus potentially reading or modifying data in an OpenStack Block Storage volume.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2017-12154

почти 9 лет назад

The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2017-12153

около 9 лет назад

A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2017-12151

около 8 лет назад

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2017-12150

около 8 лет назад

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

CVSS3: 7.4
EPSS: Средний
ubuntu логотип

CVE-2017-12149

почти 9 лет назад

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CVSS3: 9.8
EPSS: Критический
ubuntu логотип

CVE-2017-12146

около 9 лет назад

The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2017-12145

около 9 лет назад

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12144

около 9 лет назад

In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12143

около 9 лет назад

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12142

около 9 лет назад

In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12141

около 9 лет назад

In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12140

около 9 лет назад

The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12137

около 9 лет назад

arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12136

около 9 лет назад

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12135

около 9 лет назад

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12134

около 9 лет назад

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12133

около 9 лет назад

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-12157

In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access.

CVSS3: 4.3
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12156

Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.

CVSS3: 6.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12155

A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenStack as though the attacker were the OpenStack service, thus potentially reading or modifying data in an OpenStack Block Storage volume.

CVSS3: 6.3
0%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-12154

The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.

CVSS3: 7.1
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-12153

A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.

CVSS3: 4.4
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12151

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack.

CVSS3: 7.4
5%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2017-12150

It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text.

CVSS3: 7.4
13%
Средний
около 8 лет назад
ubuntu логотип
CVE-2017-12149

In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter method in the ReadOnlyAccessFilter of the HTTP Invoker does not restrict classes for which it performs deserialization and thus allowing an attacker to execute arbitrary code via crafted serialized data.

CVSS3: 9.8
91%
Критический
почти 9 лет назад
ubuntu логотип
CVE-2017-12146

The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a store operation that involve different overrides.

CVSS3: 7
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12145

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12144

In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12143

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12142

In ytnef 1.9.2, an invalid memory read vulnerability was found in the function SwapDWord in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12141

In ytnef 1.9.2, a heap-based buffer overflow vulnerability was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a crafted file.

CVSS3: 5.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12140

The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.

CVSS3: 6.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12137

arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

CVSS3: 8.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12136

Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

CVSS3: 7.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12135

Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

CVSS3: 8.8
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12134

The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12133

Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.

CVSS3: 5.9
2%
Низкий
около 9 лет назад

Уязвимостей на страницу