CVE-2017-12189
- EPSS 0.05%
- Published 10.01.2018 19:29:00
- Last modified 21.11.2024 03:09:01
It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8...
CVE-2017-15131
- EPSS 0.12%
- Published 09.01.2018 21:29:00
- Last modified 21.11.2024 03:14:07
It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux...
CVE-2017-15129
- EPSS 0.07%
- Published 09.01.2018 19:29:00
- Last modified 21.11.2024 03:14:07
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in ne...
CVE-2014-1859
- EPSS 0.07%
- Published 08.01.2018 19:29:00
- Last modified 21.11.2024 02:05:10
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2014-8119
- EPSS 2.41%
- Published 29.12.2017 22:29:00
- Last modified 20.04.2025 01:37:25
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
CVE-2016-3695
- EPSS 0.03%
- Published 29.12.2017 15:29:00
- Last modified 20.04.2025 01:37:25
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelev...
- EPSS 1.09%
- Published 18.12.2017 19:29:00
- Last modified 20.04.2025 01:37:25
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server...
CVE-2017-15104
- EPSS 0.09%
- Published 18.12.2017 19:29:00
- Last modified 20.04.2025 01:37:25
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.
CVE-2017-15121
- EPSS 0.07%
- Published 07.12.2017 02:29:13
- Last modified 20.04.2025 01:37:25
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
CVE-2017-15116
- EPSS 0.05%
- Published 30.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).