CVE-2017-3239
published 2017-01-27CVE-2017-3239: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are…
PriorityP49low3.3CVSS 3.0
AVLACLPRLUINSUCLINAN
EPSS
0.42%
34.1th percentile
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 3.3 (Confidentiality impacts).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nokogiri | nokogiri | >= 0 < 1.8.2 | 1.8.2 |
| oracle | glassfish_server | — | — |
| oracle | glassfish_server | — | — |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w7r7-9r25-wvh9: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration)
ghsa_unreviewed·2022-05-17
CVE-2017-3239 [LOW] CWE-200 GHSA-w7r7-9r25-wvh9: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration)
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to compromise Oracle GlassFish Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 3.3 (Confidentiality impacts).
GHSA
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
ghsa·2022-05-14
CVE-2017-15412 [HIGH] CWE-416 Nokogiri gem, via libxml, is affected by DoS vulnerabilities
Nokogiri gem, via libxml, is affected by DoS vulnerabilities
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: uxss in v8
vendor_redhat·2017-12-14·CVSS 6.1
CVE-2017-15429 [MEDIUM] chromium-browser: uxss in v8
chromium-browser: uxss in v8
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
Red Hat
chromium-browser: cross origin information disclosure in skia
vendor_redhat·2017-12-06·CVSS 5.3
CVE-2017-15417 [MEDIUM] chromium-browser: cross origin information disclosure in skia
chromium-browser: cross origin information disclosure in skia
Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Red Hat
chromium-browser: insufficient blocking of javascript in omnibox
vendor_redhat·2017-12-06·CVSS 6.1
CVE-2017-15427 [MEDIUM] chromium-browser: insufficient blocking of javascript in omnibox
chromium-browser: insufficient blocking of javascript in omnibox
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15411 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: out of bounds write in skia
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15409 [HIGH] chromium-browser: out of bounds write in skia
chromium-browser: out of bounds write in skia
Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: cross origin leak of redirect url in blink
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15419 [MEDIUM] chromium-browser: cross origin leak of redirect url in blink
chromium-browser: cross origin leak of redirect url in blink
Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.
Red Hat
chromium-browser: use of uninitialized value in skia
vendor_redhat·2017-12-06·CVSS 4.3
CVE-2017-15418 [MEDIUM] chromium-browser: use of uninitialized value in skia
chromium-browser: use of uninitialized value in skia
Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Red Hat
chromium-browser: integer overflow in icu
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15422 [MEDIUM] chromium-browser: integer overflow in icu
chromium-browser: integer overflow in icu
Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Package: icu (Red Hat Enterprise Linux 6) - Will not fix
Package: icu (Red Hat Enterprise Linux 7) - Will not fix
Package: icu (Red Hat Enterprise Linux 8) - Not affected
Red Hat
chromium-browser: out of bounds write in quic
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15407 [HIGH] chromium-browser: out of bounds write in quic
chromium-browser: out of bounds write in quic
Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.
Red Hat
chromium-browser: url spoof in omnibox
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15425 [MEDIUM] chromium-browser: url spoof in omnibox
chromium-browser: url spoof in omnibox
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: url spoof in omnibox
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15424 [MEDIUM] chromium-browser: url spoof in omnibox
chromium-browser: url spoof in omnibox
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15412 [HIGH] libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
libxml2: Use after free in xmlXPathCompOpEvalPositionalPredicate() function in xpath.c
Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
A use-after-free flaw was found in the libxml2 library. An attacker could use this flaw to cause an application linked against libxml2 to crash when parsing a specially crafted XML file.
Package: libxml2 (Red Hat Enterprise Linux 6) - Out of support scope
Package: libxml2 (Red Hat Enterprise Linux 8) - Not affected
Package: mingw-libxml2 (Red Hat Enterprise Linux 8) - Affected
Package: libxml2 (Red Hat JBoss Enterprise Web Server 3) - Will not fix
Red Hat
chromium-browser: url spoof in omnibox
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15426 [MEDIUM] chromium-browser: url spoof in omnibox
chromium-browser: url spoof in omnibox
Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.
Red Hat
chromium-browser: issue with spake implementation in boringssl
vendor_redhat·2017-12-06·CVSS 5.3
CVE-2017-15423 [MEDIUM] chromium-browser: issue with spake implementation in boringssl
chromium-browser: issue with spake implementation in boringssl
Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.
Red Hat
chromium-browser: type confusion in webassembly
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15413 [HIGH] chromium-browser: type confusion in webassembly
chromium-browser: type confusion in webassembly
Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Red Hat
chromium-browser: out of bounds read in blink
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15416 [MEDIUM] chromium-browser: out of bounds read in blink
chromium-browser: out of bounds read in blink
Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.
Red Hat
chromium-browser: heap buffer overflow in pdfium
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15408 [HIGH] chromium-browser: heap buffer overflow in pdfium
chromium-browser: heap buffer overflow in pdfium
Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.
Red Hat
chromium-browser: use after free in pdfium
vendor_redhat·2017-12-06·CVSS 8.8
CVE-2017-15410 [HIGH] chromium-browser: use after free in pdfium
chromium-browser: use after free in pdfium
Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
Red Hat
chromium-browser: pointer information disclosure in ipc call
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15415 [MEDIUM] chromium-browser: pointer information disclosure in ipc call
chromium-browser: pointer information disclosure in ipc call
Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.
Red Hat
chromium-browser: url spoofing in omnibox
vendor_redhat·2017-12-06·CVSS 6.5
CVE-2017-15420 [MEDIUM] chromium-browser: url spoofing in omnibox
chromium-browser: url spoofing in omnibox
Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-01-27
Published