|
1211
|
6.5
4.0
|
MEDIUM
Network
|
It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a disabled account would be able to bypass security re…
|
CWE-20
Improper Input Validation
|
CVE-2017-12197
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:09
2018-01-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1212
|
5.5
4.9
|
MEDIUM
Local
|
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15128
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2018-01-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1213
|
5.5
4.9
|
MEDIUM
Local
|
A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local den…
|
-
|
CVE-2017-15127
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2018-01-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1214
|
7.8
4.6
|
HIGH
Local
|
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This is…
|
NVD-CWE-noinfo
|
CVE-2017-12189
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:09
2018-01-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1215
|
7.8
4.6
|
HIGH
Local
|
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs bef…
|
-
|
CVE-2017-15131
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2018-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1216
|
4.7
4.9
|
MEDIUM
Local
|
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::…
|
CWE-362
Race Condition
|
CVE-2017-15129
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2018-01-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1217
|
5.5
2.1
|
MEDIUM
Local
|
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink at…
|
CWE-59
Link Following
|
CVE-2014-1859
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:05
2018-01-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1218
|
7.5
5.0
|
HIGH
Network
|
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
|
CWE-20
Improper Input Validation
|
CVE-2014-8119
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 11:18
2017-12-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1219
|
5.5
2.1
|
MEDIUM
Local
|
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disab…
|
CWE-74
Injection
|
CVE-2016-3695
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:50
2017-12-30
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1220
|
7.8
2.1
|
HIGH
Local
|
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi…
|
-
|
CVE-2017-15104
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2017-12-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|