CVE-2016-9595
- EPSS 0.04%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:28
A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.
CVE-2017-7470
- EPSS 0.91%
- Veröffentlicht 27.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:31:58
It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py.
CVE-2017-12175
- EPSS 0.47%
- Veröffentlicht 26.07.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:59
Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality.
CVE-2017-7538
- EPSS 0.25%
- Veröffentlicht 26.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:07
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other Satellite users.
CVE-2018-2973
- EPSS 0.12%
- Veröffentlicht 18.07.2018 13:29:03
- Zuletzt bearbeitet 21.11.2024 04:04:52
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unau...
CVE-2018-2940
- EPSS 0.22%
- Veröffentlicht 18.07.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:04:47
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows u...
CVE-2018-2952
- EPSS 0.06%
- Veröffentlicht 18.07.2018 13:29:02
- Zuletzt bearbeitet 21.11.2024 04:04:49
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult t...
CVE-2017-2672
- EPSS 0.54%
- Veröffentlicht 21.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those sy...
CVE-2018-1090
- EPSS 0.29%
- Veröffentlicht 18.06.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
CVE-2016-1000338
- EPSS 0.38%
- Veröffentlicht 01.06.2018 20:29:00
- Zuletzt bearbeitet 05.05.2025 14:14:28
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in s...