CVE-2017-8952
published 2018-02-15CVE-2017-8952: A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
4.93%
91.1th percentile
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hewlett_packard_enterprise | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| hp | sitescope | — | — |
| linux | linux_kernel | >= 0 < 4.4.0-116.140 | 4.4.0-116.140 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r79f-f47p-h2gf: A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11
ghsa_unreviewed·2022-05-14
CVE-2017-8952 [HIGH] CWE-200 GHSA-r79f-f47p-h2gf: A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11
A Disclosure of Sensitive Information vulnerability in HPE SiteScope version v11.2x, v11.3x was found.
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
osv·2018-02-22·CVSS 5.5
CVE-2017-17712 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel
did not properly track reference counts when merging buffers. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2017-1219
OSV
linux-lts-xenial, linux-aws vulnerabilities
osv·2018-02-22·CVSS 5.5
linux-lts-xenial, linux-aws vulnerabilities
linux-lts-xenial, linux-aws vulnerabilities
USN-3582-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 LTS.
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the
Linux kernel contained a race condition leading to uninitialized pointer
usage. A local attacker could use this to cause a denial of service or
possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4
filesystems in the Linux kernel improperly handled xattr block caching. A
local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsys
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/99333http://www.securitytracker.com/id/1038791https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03763en_ushttp://www.securityfocus.com/bid/99333http://www.securitytracker.com/id/1038791https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbgn03763en_us
2018-02-15
Published