CVE-2017-3247
published 2017-01-27CVE-2017-3247: Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 2.1.1, 3.0.1…
PriorityP422medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
1.15%
63.0th percentile
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle GlassFish Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle GlassFish Server accessible data. CVSS v3.0 Base Score 4.3 (Integrity impacts).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | glassfish_server | — | — |
| oracle | glassfish_server | — | — |
| oracle | glassfish_server | — | — |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7830 Mozilla: Cross-origin URL information leak through Resource Timing API (MFSA 2017-25)
bugzilla·2017-11-15·CVSS 6.5
CVE-2017-7830 [MEDIUM] CVE-2017-7830 Mozilla: Cross-origin URL information leak through Resource Timing API (MFSA 2017-25)
CVE-2017-7830 Mozilla: Cross-origin URL information leak through Resource Timing API (MFSA 2017-25)
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-25/#CVE-2017-7830
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Jun Kokatsu
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:3247 https://access.redhat.com/errata/RHSA-2017:3247
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:3372 https://access.red
Bugzilla
CVE-2017-7828 Mozilla: Use-after-free of PressShell while restyling layout (MFSA 2017-25)
bugzilla·2017-11-15·CVSS 9.8
CVE-2017-7828 [CRITICAL] CVE-2017-7828 Mozilla: Use-after-free of PressShell while restyling layout (MFSA 2017-25)
CVE-2017-7828 Mozilla: Use-after-free of PressShell while restyling layout (MFSA 2017-25)
A use-after-free vulnerability can occur when flushing and resizing layout because the PressShell object has been freed while still in use. This results in a potentially exploitable crash during these operations.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-25/#CVE-2017-7828
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:3247 https://access.redhat.com/errata/RHSA-2017:3247
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2017:3372
2017-01-27
Published