CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104020  CVE-2017-7200  Candidate  An SSRF issue was discovered in OpenStack Glance before Newton. The "copy_from" feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as "http://localhost:22". This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.  Assigned (20170320)  None (candidate not yet proposed)    View
104019  CVE-2017-7199  Candidate  Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.  Assigned (20170320)  None (candidate not yet proposed)    View
104018  CVE-2017-7198  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170320)  None (candidate not yet proposed)    View
104017  CVE-2017-7197  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170320)  None (candidate not yet proposed)    View
104016  CVE-2017-7196  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170320)  None (candidate not yet proposed)    View

Page 140 of 20943, showing 5 records out of 104715 total, starting on record 696, ending on 700

Actions