Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-27 CVE-2017-2649 Improper Certificate Validation vulnerability in Jenkins Active Directory
It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.
network
high complexity
jenkins CWE-295
8.1
2018-07-27 CVE-2016-9577 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling.
network
low complexity
spice-project redhat debian CWE-119
8.8
2018-07-27 CVE-2017-2634 It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions.
network
low complexity
linux redhat
7.5
2018-07-27 CVE-2018-1056 Out-of-bounds Read vulnerability in multiple products
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files.
local
low complexity
advancemame canonical debian CWE-125
7.8
2018-07-27 CVE-2017-2646 Infinite Loop vulnerability in Redhat Keycloak
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop.
network
low complexity
redhat CWE-835
7.5
2018-07-27 CVE-2017-2630 Unspecified vulnerability in Qemu
A stack buffer overflow flaw was found in the Quick Emulator (QEMU) before 2.9 built with the Network Block Device (NBD) client support.
network
low complexity
qemu
8.8
2018-07-27 CVE-2017-2624 Information Exposure vulnerability in multiple products
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.
local
high complexity
x-org debian CWE-200
7.0
2018-07-27 CVE-2017-2590 Permission Issues vulnerability in multiple products
A vulnerability was found in ipa before 4.4.
network
low complexity
freeipa redhat CWE-275
8.1
2018-07-27 CVE-2017-2581 Out-of-bounds Write vulnerability in Netpbm Project Netpbm
An out-of-bounds write vulnerability was found in netpbm before 10.61.
local
low complexity
netpbm-project CWE-787
7.8
2018-07-27 CVE-2017-2580 Out-of-bounds Write vulnerability in Netpbm Project Netpbm 10.61.00
An out-of-bounds write vulnerability was found in netpbm before 10.61.
local
low complexity
netpbm-project CWE-787
7.8