CVE-2017-2616

CVSS v3 Score
4.7
Medium
CVSS v2 Score
4.7
Medium

Vulnerability Description

A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.

CVSS:5.9(Medium)

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be tr...

CVSS:3.3(Low)

Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

CVSS:6.5(Medium)

A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handl...

CVSS:6.5(Medium)

Debug tool in Secomea SiteManager allows logged-in administrator to modify system state in an unintended manner.

CVSS:6.5(Medium)

SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views...

CVSS:6.5(Medium)

Privilege Defined With Unsafe Actions in GitHub repository pimcore/pimcore prior to 10.5.23.