|
1221
|
8.8
9.0
|
HIGH
Network
|
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote …
|
-
|
CVE-2017-15103
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2017-12-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
5.5
4.9
|
MEDIUM
Local
|
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
|
-
|
CVE-2017-15121
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:14
2017-12-7
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
5.5
4.9
|
MEDIUM
Local
|
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15116
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:14
2017-12-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
6.3
6.9
|
MEDIUM
Physics
|
The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15102
|
cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux:5.0:*
|
|
|
|
|
2024-11-21 12:14
2017-11-16
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
7.8
7.2
|
HIGH
Local
|
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability w…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000253
|
cpe:2.3:o:redhat:enterprise_linux:7.3:* cpe:2.3:o:redhat:enterprise_linux:7.2:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-04-22 03:00
2017-10-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
7.8
7.2
|
HIGH
Local
|
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-1000111
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:04
2017-10-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
5.5
2.1
|
MEDIUM
Local
|
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot re…
|
CWE-254
7PK - Security Features
|
CVE-2015-7837
|
cpe:2.3:o:redhat:enterprise_linux:7.3:* cpe:2.3:o:redhat:enterprise_linux:7.2:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 11:37
2017-09-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
4.7
4.7
|
MEDIUM
Local
|
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by…
|
CWE-362
Race Condition
|
CVE-2015-7553
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 11:36
2017-09-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
7.0
7.6
|
HIGH
Local
|
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descript…
|
CWE-416
Use After Free
|
CVE-2017-10661
|
cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 12:06
2017-08-20
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
8.8
9.3
|
HIGH
Network
|
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2017-3106
|
cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:24
2017-08-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|