CVE-2017-15097
- EPSS 0.03%
- Published 27.07.2018 20:29:00
- Last modified 21.11.2024 03:14:03
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
CVE-2017-15101
- EPSS 0.32%
- Published 27.07.2018 20:29:00
- Last modified 21.11.2024 03:14:04
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
CVE-2017-2616
- EPSS 0.06%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
CVE-2017-2618
- EPSS 0.05%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
CVE-2017-2620
- EPSS 0.77%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2017-2626
- EPSS 0.03%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
CVE-2017-2633
- EPSS 0.56%
- Published 27.07.2018 19:29:00
- Last modified 21.11.2024 03:23:52
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use t...
CVE-2017-2590
- EPSS 0.18%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:47
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable,...
CVE-2017-2625
- EPSS 0.03%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:51
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing...
CVE-2017-2640
- EPSS 1%
- Published 27.07.2018 18:29:00
- Last modified 21.11.2024 03:23:53
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.