CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93621  CVE-2016-6801  Candidate  Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.  Assigned (20160812)  None (candidate not yet proposed)    View
93622  CVE-2016-6802  Candidate  Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.  Assigned (20160812)  None (candidate not yet proposed)    View
93623  CVE-2016-6803  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160812)  None (candidate not yet proposed)    View
93624  CVE-2016-6804  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160812)  None (candidate not yet proposed)    View
93625  CVE-2016-6805  Candidate  Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.  Assigned (20160812)  None (candidate not yet proposed)    View

Page 18725 of 20943, showing 5 records out of 104715 total, starting on record 93621, ending on 93625

Actions