CVE-2015-2017
published 2015-11-08CVE-2015-2017: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8…
PriorityP422medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.88%
77.2th percentile
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libmspack vulnerabilities
osv·2025-10-01·CVSS 4.3
CVE-2015-4467 libmspack vulnerabilities
libmspack vulnerabilities
Jakub Wilk discovered that libmspack did not correctly handle certain
integer operations and bounds checking. A remote attacker could possibly
use this issue to cause a denial of service. (CVE-2015-4467, CVE-2015-4468,
CVE-2015-4469, CVE-2015-4472)
It was discovered that libmspack incorrectly handled certain malformed CAB
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service. (CVE-2017-11423)
It was discovered that libmspack incorrectly handled certain malformed CHM
files. A remote attacker could use this issue to cause libmspack to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2017-6419)
Hanno Böck discovered that libmspack incorrectly handled certain CHM files.
An attac
OSV
nova vulnerabilities
osv·2023-02-13·CVSS 3.3
CVE-2015-9543 nova vulnerabilities
nova vulnerabilities
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service attack. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-1
GHSA
GHSA-8r6c-52gg-72c8: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6
ghsa_unreviewed·2022-05-17
CVE-2015-2017 [MEDIUM] GHSA-8r6c-52gg-72c8: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
Red Hat
cpio: --no-absolute-filenames bypass via symlinks
vendor_redhat·2017-06-05·CVSS 1.9
CVE-2017-7516 [LOW] CWE-22 cpio: --no-absolute-filenames bypass via symlinks
cpio: --no-absolute-filenames bypass via symlinks
[REJECTED CVE] A vulnerability was identified in the GNU cpio package where the --no-absolute-filenames option, intended to restrict extraction to the current directory, can be bypassed using crafted symlinks. During extraction, cpio will first create the symlink and then follow it for subsequent entries, allowing a malicious archive to write files outside the intended directory (e.g., /tmp/file). An attacker could exploit this by tricking a user, into extracting such an archive, potentially leading to arbitrary file creation, privilege escalation, or data corruption.
Statement: This flaw was found to be a duplicate of CVE-2015-1197. Please see https://access.redhat.com/security/cve/CVE-2015-1197 for information about affected products an
Red Hat
salt: local_batch client external authentication not respected
vendor_redhat·2017-01-20·CVSS 8.8
CVE-2017-5192 [HIGH] salt: local_batch client external authentication not respected
salt: local_batch client external authentication not respected
When using the local_batch client from salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2, external authentication is not respected, enabling all authentication to be bypassed.
Statement: This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.
Mitigation: Disable salt-api for mitigation.
Package: salt (Red Hat Ceph Storage 1.3) - Not affected
Package: salt (Red Hat Ceph Storage 2) - Not affected
Package: salt (Red Hat Storage Console 2) - Not affected
Red Hat
salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
vendor_redhat·2017-01-20·CVSS 8.8
CVE-2017-5200 [HIGH] salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
salt: Salt-api allows arbitrary command execution on a salt-master via Salt's ssh_client
Salt-api in SaltStack Salt before 2015.8.13, 2016.3.x before 2016.3.5, and 2016.11.x before 2016.11.2 allows arbitrary command execution on a salt-master via Salt's ssh_client.
Statement: This issue did not affect the versions of the salt as shipped with Red Hat Ceph Storage 1.3, Red Hat Ceph Storage 2, and Red Hat Storage Console 2 as salt-api and salt-ssh are not shipped with these products.
Mitigation: Disable salt-api for mitigation.
Package: salt (Red Hat Ceph Storage 1.3) - Not affected
Package: salt (Red Hat Ceph Storage 2) - Not affected
Package: salt (Red Hat Storage Console 2) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9099 CVE-2015-9100 CVE-2017-11720 CVE-2017-13712 CVE-2017-15018 CVE-2017-15019 CVE-2017-15045 CVE-2017-15046 CVE-2017-9410 CVE-2017-9411 CVE-2017-9412 CVE-2017-8419 lame: Multiple vulnerabili
bugzilla·2017-07-12·CVSS 5.5
CVE-2015-9099 [MEDIUM] CVE-2015-9099 CVE-2015-9100 CVE-2017-11720 CVE-2017-13712 CVE-2017-15018 CVE-2017-15019 CVE-2017-15045 CVE-2017-15046 CVE-2017-9410 CVE-2017-9411 CVE-2017-9412 CVE-2017-8419 lame: Multiple vulnerabili
CVE-2015-9099 CVE-2015-9100 CVE-2017-11720 CVE-2017-13712 CVE-2017-15018 CVE-2017-15019 CVE-2017-15045 CVE-2017-15046 CVE-2017-9410 CVE-2017-9411 CVE-2017-9412 CVE-2017-8419 lame: Multiple vulnerabilities [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also m
Bugzilla
CVE-2016-10229 kernel: net: Unsafe second checksum calculation in udp.c
bugzilla·2017-04-06·CVSS 9.8
CVE-2016-10229 [CRITICAL] CVE-2016-10229 kernel: net: Unsafe second checksum calculation in udp.c
CVE-2016-10229 kernel: net: Unsafe second checksum calculation in udp.c
A flaw was found in the Linux kernel which allows remote attackers to crash the system or corrupt kernel memory, possibly leading to arbitrary code execution, via UDP traffic that triggers an unsafe second checksum calculation during the execution of a recv system call with the MSG_PEEK flag.
Upstream patch:
https://github.com/torvalds/linux/commit/197c949e7798fbf28cfadc69d9ca0c2abbf93191
References:
http://source.android.com/security/bulletin/2017-04-01.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1440624]
---
This fix was committed upstream in the 4.5 kernel merge window (Dec 2015). It has never impacted any of the currently supported versions of Fedora.
---
State
Bugzilla
CVE-2015-8870 libtiff: Integer overflow in tools/bmp2tiff.c
bugzilla·2016-12-08·CVSS 7.4
CVE-2015-8870 [HIGH] CVE-2015-8870 libtiff: Integer overflow in tools/bmp2tiff.c
CVE-2015-8870 libtiff: Integer overflow in tools/bmp2tiff.c
Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows
remote attackers to cause a denial of service (heap-based buffer
over-read), or possibly obtain sensitive information from process
memory, via crafted width and length values in RLE4 or RLE8 data in a
BMP file.
References:
http://www.floyd.ch/?p=874
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2017:0225 https://rhn.redhat.com/errata/RHSA-2017-0225.html
Fortinet
The Analysis of Apache Struts 1 Form Field Input Validation Bypass (CVE-2015-0899)
blogs_fortinet·2017-10-25·CVSS 7.5
CVE-2015-0899 [HIGH] The Analysis of Apache Struts 1 Form Field Input Validation Bypass (CVE-2015-0899)
FORTIGUARD LABS THREAT RESEARCH
The Analysis of Apache Struts 1 Form Field Input Validation Bypass (CVE-2015-0899)
By Dehui Yin | October 25, 2017
Apache Struts 1 is a popularly used JAVA EE web application framework. It offers many kinds of validators to filter user input by using the Apache Common Validator library, which is both convenient and fast. However, a bug in Apache Struts can be used to easily bypass the input validation process, allowing an attacker to submit arbitrary dirty data to the database, possibly resulting in a cross-site scripting attack when the user views the JSP file that refers directly to the corrupted data.
This potential Input Validation Bypass vulnerability is caused by an error in both ValidatorForm.java and DynaValidatorForm.java when initializing the va
http://www-01.ibm.com/support/docview.wss?uid=swg1PI45266http://www-01.ibm.com/support/docview.wss?uid=swg21966837http://www.securityfocus.com/bid/78457http://www.securitytracker.com/id/1034096http://www-01.ibm.com/support/docview.wss?uid=swg1PI45266http://www-01.ibm.com/support/docview.wss?uid=swg21966837http://www.securityfocus.com/bid/78457http://www.securitytracker.com/id/1034096
2015-11-08
Published