CVE-2017-1793
published 2018-07-10CVE-2017-1793: IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.66%
47.3th percentile
IBM Rational Quality Manager 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137038.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | — | — |
| ibm | rational_quality_manager | 5.0 – 5.0.2 | — |
| ibm | rational_quality_manager | 6.0 – 6.0.5 | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
bugzilla·2017-07-18·CVSS 8.1
CVE-2017-7771 [HIGH] CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
CVE-2017-7771 graphite2: out of bounds read in "graphite2::Pass::readPass"
An out of bounds read flaw related to "graphite2::Pass::readPass" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7777 [HIGH] CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
CVE-2017-7777 graphite2: use of uninitialized memory "graphite2::GlyphCache::Loader::read_glyph"
The use of uninitialized memory related to "graphite2::GlyphCache::Loader::read_glyph" has been reported in graphite2. An attacker could possibly exploit this flaw to negatively impact the execution of an application
using graphite2 in unknown ways.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7773 [HIGH] CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
CVE-2017-7773 graphite2: heap-buffer-overflow write "lz4::decompress" (src/Decompressor)
A heap-based buffer overflow flaw related to "lz4::decompress" (src/Decompressor) has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
bugzilla·2017-07-18·CVSS 9.1
CVE-2017-7774 [CRITICAL] CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
CVE-2017-7774 graphite2: out of bounds read "graphite2::Silf::readGraphite"
An out of bounds read flaw related to "graphite2::Silf::readGraphite" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
bugzilla·2017-07-18·CVSS 8.8
CVE-2017-7772 [HIGH] CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
CVE-2017-7772 graphite2: heap-buffer-overflow write "lz4::decompress" (CVE-2017-7772)
A heap-based buffer overflow flaw related to "lz4::decompress" has been reported in graphite2. A remote attacker could exploit this issue to cause a crash, or, possibly, execute arbitrary code.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7775 graphite2: assertion error "size() > n"
bugzilla·2017-07-18·CVSS 9.8
CVE-2017-7775 [CRITICAL] CVE-2017-7775 graphite2: assertion error "size() > n"
CVE-2017-7775 graphite2: assertion error "size() > n"
An assertion error has been reported in graphite2. An attacker could possibly exploit this flaw to cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
Bugzilla
CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
bugzilla·2017-07-18·CVSS 8.1
CVE-2017-7776 [HIGH] CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
CVE-2017-7776 graphite2: heap-buffer-overflow read "graphite2::Silf::getClassGlyph"
An out of bounds read flaw related to "graphite2::Silf::getClassGlyph" has been reported in graphite2. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Holger Fuhrmannek, Tyson Smith
---
External References:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-16/#CVE-2017-7778
https://sourceforge.net/p/silgraphite/mailman/message/35824024/
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:1793 https://access.redhat.com/errata/RHSA-2017:1793
2018-07-10
Published